AWS Certified Security – SpecialtyDomain 5: Data ProtectionEasy
A media streaming company uses Amazon DynamoDB to store user preferences and viewing history. Due to compliance requirements, all data at rest in DynamoDB must be encrypted with customer-managed keys (CMKs) from AWS Key Management Service (KMS). The security team needs to ensure that these CMKs are automatically rotated annually for enhanced security. Which option fulfills this requirement?
- AImplement client-side encryption with a custom key management solution that rotates keys annually, then store encrypted data in DynamoDB.
- BUse DynamoDB encryption with AWS-owned keys, as they are automatically rotated by AWS.
- CEnable automatic key rotation for the AWS KMS customer managed key (CMK) used for DynamoDB encryption.
- DCreate a new KMS CMK annually and manually update the DynamoDB table encryption settings to use the new CMK.
Show answer & explanationAnswer & explanation
Correct answer: C. Enable automatic key rotation for the AWS KMS customer managed key (CMK) used for DynamoDB encryption.
AWS KMS provides a built-in feature for automatic key rotation for customer-managed keys (CMKs). Enabling this feature for the CMK used to encrypt the DynamoDB table ensures that the keys are rotated annually without manual intervention, meeting the security requirement.
Why the other options are wrong
- A. Client-side encryption for DynamoDB is possible but adds significant complexity and management overhead. The requirement can be met more simply with native KMS features for 'data at rest' encryption.
- B. AWS-owned keys are rotated automatically, but the requirement specifically states 'customer-managed keys (CMKs)', which are different.
- D. Manually creating and updating CMKs is cumbersome and prone to error, not an 'automatic' solution.
KMS CMK Automatic Key Rotation
A feature in AWS Key Management Service (KMS) that automatically generates new cryptographic material for a customer-managed key (CMK) annually, without changing the CMK's ID or requiring re-encryption of data.
- Enhances security by regularly changing the underlying key material.
- Applies to customer-managed keys (CMKs), not AWS-managed or AWS-owned keys.
- Does not affect existing encrypted data; data can still be decrypted with the CMK.
Memory trick: Rotate your CMKs, keep your data safe, effortlessly.