AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium
A healthcare provider stores sensitive patient health information (PHI) in an Amazon S3 bucket. They are required to encrypt all new objects uploaded to this bucket by default. Additionally, they need to ensure that the encryption keys are centrally managed and that access to these keys is auditable. Which S3 encryption configuration meets these requirements while providing central key management and auditability?
- AImplement client-side encryption using the AWS Encryption SDK with a customer-provided encryption key (SSE-C).
- BConfigure S3 bucket default encryption to use Server-Side Encryption with S3-managed keys (SSE-S3).
- CUse S3 bucket policies to enforce that only objects encrypted with customer-provided encryption keys (SSE-C) are allowed.
- DConfigure S3 bucket default encryption to use Server-Side Encryption with AWS Key Management Service (AWS KMS) customer managed keys (CMKs).
Show answer & explanationAnswer & explanation
Correct answer: D. Configure S3 bucket default encryption to use Server-Side Encryption with AWS Key Management Service (AWS KMS) customer managed keys (CMKs).
SSE-KMS, configured as default bucket encryption, ensures all new objects are encrypted automatically. Using a KMS CMK provides central key management, allows for granular key policies, and integrates with AWS CloudTrail for auditing all key usage, fulfilling all stated requirements.
Why the other options are wrong
- A. Client-side encryption requires application changes and places the burden of key management and auditing entirely on the customer's application, without the benefits of central KMS management and CloudTrail integration for key usage.
- B. SSE-S3 encrypts objects by default but does not offer central key management or auditability of key usage to the customer; AWS manages these aspects transparently.
- C. While enforcing SSE-C via bucket policies ensures encryption, it shifts the key management burden entirely to the client application and doesn't provide central management or auditability through AWS services for key usage.
SSE-KMS for Central Key Management & Audit
Server-Side Encryption with AWS KMS customer managed keys (CMKs) provides encryption at rest for Amazon S3 objects, offering central key management, granular access control via key policies, and auditability of key usage through AWS CloudTrail.
- CMKs are managed within AWS KMS, providing a central point of control.
- Key policies define who can use and manage the CMK.
- All API calls to KMS for key usage are logged in AWS CloudTrail for auditing.
- Can be set as default bucket encryption for automatic encryption of new objects.
Memory trick: KMS CMK: Central, Managed, Audited.