AWS Certified Security – SpecialtyDomain 5: Data ProtectionEasy
A media streaming company uses Amazon DynamoDB to store user preferences and viewing history. Due to performance requirements, the table is configured for on-demand capacity. The company's compliance regulations mandate that all data at rest must be encrypted with customer-managed keys (CMKs) from AWS KMS. What is the most straightforward way to ensure that the DynamoDB table's data is encrypted with the specified CMK?
- ADynamoDB encrypts all data at rest with AWS-owned keys by default, and this cannot be changed.
- BUse a custom application to encrypt data before writing it to DynamoDB, and decrypt it upon retrieval.
- CConfigure an IAM policy for the DynamoDB table to enforce the use of a specific KMS CMK for encryption.
- DEnable the 'Encryption at rest' option in the DynamoDB table settings and select the desired KMS CMK.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable the 'Encryption at rest' option in the DynamoDB table settings and select the desired KMS CMK.
DynamoDB offers the option to encrypt data at rest using either AWS-owned keys (default), AWS-managed keys (AWS KMS), or customer-managed keys (AWS KMS CMKs). To use a specific customer-managed CMK, you simply enable the 'Encryption at rest' setting in the DynamoDB table configuration and choose your desired KMS CMK.
Why the other options are wrong
- A. This is incorrect. While DynamoDB encrypts all data at rest by default, it offers flexibility to choose different key types (AWS-owned, AWS-managed, customer-managed).
- B. While client-side encryption is an option for ultimate control, the question specifically asks for encryption *with KMS CMKs* and 'most straightforward way', implying leveraging DynamoDB's native integration rather than a custom application, which adds overhead.
- C. IAM policies grant permissions to principals to *use* resources or keys, but they don't configure the encryption settings *of* the DynamoDB table itself. The table's encryption key is a configuration property of the table.
DynamoDB Encryption at Rest
Amazon DynamoDB encrypts all data at rest by default. Customers can choose between AWS-owned keys, AWS-managed keys (KMS), or customer-managed keys (KMS CMKs) for encryption, providing flexibility for compliance.
- Always encrypted at rest.
- Choice of AWS-owned, AWS-managed, or customer-managed (KMS CMK) keys.
- Configured in table settings during creation or modification.
- No performance impact for encryption.
Memory trick: DynamoDB's 'Encryption' is a 'Switch' you control with KMS.