AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium

A financial institution is developing a new data analytics platform that processes highly sensitive customer financial data. They need to ensure that all data in Amazon S3 is encrypted at rest and that the encryption keys are automatically rotated annually for enhanced security. The solution should minimize manual intervention for key rotation. Which S3 encryption configuration, combined with key management, best meets these requirements?

  1. AConfigure S3 bucket default encryption to use Server-Side Encryption with S3-managed keys (SSE-S3).
  2. BConfigure S3 bucket default encryption to use Server-Side Encryption with AWS Key Management Service (AWS KMS) customer managed keys (CMKs) with automatic key rotation enabled.
  3. CUse a custom AWS Lambda function to periodically re-encrypt objects in S3 with new keys generated by AWS KMS.
  4. DImplement client-side encryption using the AWS Encryption SDK with customer-provided encryption keys (SSE-C), and manually rotate keys annually.
Show answer & explanation

Correct answer: B. Configure S3 bucket default encryption to use Server-Side Encryption with AWS Key Management Service (AWS KMS) customer managed keys (CMKs) with automatic key rotation enabled.

SSE-KMS with CMKs allows S3 to encrypt objects using keys managed in KMS. KMS CMKs have an optional feature for automatic annual key rotation, which satisfies the requirement for automatic annual key rotation without manual intervention, while also providing encryption at rest.

Why the other options are wrong

  • A. SSE-S3 keys are rotated automatically by AWS, but the rotation frequency is not configurable or auditable by the customer, and it's not explicitly 'annual' from the customer's perspective. It doesn't offer the same level of control as CMKs.
  • C. While a Lambda function could re-encrypt objects, this is a complex, custom solution that introduces significant operational overhead and potential downtime or data consistency issues, compared to the native automatic rotation feature of KMS CMKs.
  • D. SSE-C requires manual key management and rotation, which directly contradicts the 'minimize manual intervention for key rotation' requirement.

KMS CMK Automatic Key Rotation

AWS Key Management Service (KMS) customer managed keys (CMKs) can be configured to automatically rotate their cryptographic material annually, providing enhanced security without manual intervention for key management.

  • Applies to CMKs, not AWS-managed keys.
  • Rotates the underlying cryptographic material, but the key ID remains the same.
  • Previous key versions are retained for decryption of older data.
  • Automatically happens once a year.

Memory trick: KMS CMK Rotates Itself Annually.

More Domain 5: Data Protection questions