AWS Certified Security – SpecialtyDomain 5: Data ProtectionEasy

A media streaming company uses Amazon DynamoDB to store user preferences and viewing history. Due to performance requirements, the table is configured for on-demand capacity. The company's compliance regulations mandate that all data at rest must be encrypted with customer-managed keys (CMKs) from AWS KMS. What is the most straightforward way to ensure that the DynamoDB table's data is encrypted with the specified CMK?

  1. ADynamoDB encrypts all data at rest with AWS-owned keys by default, and this cannot be changed.
  2. BUse a custom application to encrypt data before writing it to DynamoDB, and decrypt it upon retrieval.
  3. CConfigure an IAM policy for the DynamoDB table to enforce the use of a specific KMS CMK for encryption.
  4. DEnable the 'Encryption at rest' option in the DynamoDB table settings and select the desired KMS CMK.
Show answer & explanation

Correct answer: D. Enable the 'Encryption at rest' option in the DynamoDB table settings and select the desired KMS CMK.

DynamoDB offers the option to encrypt data at rest using either AWS-owned keys (default), AWS-managed keys (AWS KMS), or customer-managed keys (AWS KMS CMKs). To use a specific customer-managed CMK, you simply enable the 'Encryption at rest' setting in the DynamoDB table configuration and choose your desired KMS CMK.

Why the other options are wrong

  • A. This is incorrect. While DynamoDB encrypts all data at rest by default, it offers flexibility to choose different key types (AWS-owned, AWS-managed, customer-managed).
  • B. While client-side encryption is an option for ultimate control, the question specifically asks for encryption *with KMS CMKs* and 'most straightforward way', implying leveraging DynamoDB's native integration rather than a custom application, which adds overhead.
  • C. IAM policies grant permissions to principals to *use* resources or keys, but they don't configure the encryption settings *of* the DynamoDB table itself. The table's encryption key is a configuration property of the table.

DynamoDB Encryption at Rest

Amazon DynamoDB encrypts all data at rest by default. Customers can choose between AWS-owned keys, AWS-managed keys (KMS), or customer-managed keys (KMS CMKs) for encryption, providing flexibility for compliance.

  • Always encrypted at rest.
  • Choice of AWS-owned, AWS-managed, or customer-managed (KMS CMK) keys.
  • Configured in table settings during creation or modification.
  • No performance impact for encryption.

Memory trick: DynamoDB's 'Encryption' is a 'Switch' you control with KMS.

More Domain 5: Data Protection questions