AWS Certified Security – SpecialtyDomain 5: Data ProtectionEasy
A media company uses Amazon S3 to store large video files that are frequently accessed by content delivery networks (CDNs). They need to ensure that all data is encrypted at rest and in transit. The company also wants to minimize operational overhead for key management. Which encryption solution meets these requirements with the least operational burden?
- AConfigure S3 bucket default encryption to use Server-Side Encryption with AWS KMS managed keys (SSE-KMS).
- BConfigure S3 bucket default encryption to use Server-Side Encryption with S3-managed keys (SSE-S3).
- CImplement client-side encryption using a customer-provided encryption key (SSE-C) before uploading objects to S3.
- DImplement client-side encryption using the AWS Encryption SDK with a customer managed key (CMK) from AWS KMS.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure S3 bucket default encryption to use Server-Side Encryption with S3-managed keys (SSE-S3).
SSE-S3 provides encryption at rest with virtually no operational overhead, as AWS manages all encryption keys and key rotation. S3 automatically encrypts data upon upload and decrypts upon download. Encryption in transit is handled by HTTPS/TLS, which is standard for S3 interactions.
Why the other options are wrong
- A. SSE-KMS provides more control over keys than SSE-S3 but introduces some operational overhead related to KMS key policies and management, which is not the 'least' operational burden.
- C. SSE-C requires the customer to manage and provide encryption keys for every object operation, which is a significant operational overhead.
- D. Client-side encryption with AWS Encryption SDK requires application-level changes and managing the CMK, which adds significant operational overhead compared to server-side options.
SSE-S3 for Minimal Overhead
Server-Side Encryption with S3-managed encryption keys (SSE-S3) automatically encrypts objects before saving them to S3 and decrypts them when downloaded, with AWS managing all key lifecycle, offering the lowest operational overhead.
- AWS manages the encryption keys completely.
- Encrypts data at rest automatically.
- Requires no changes to your application code for encryption/decryption.
- Supports encryption in transit via HTTPS/TLS.
Memory trick: Simple S3 is SSE-S3.