AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium
A global media streaming company uses Amazon DynamoDB to store user preferences and viewing history. Due to a new compliance mandate, all data stored in DynamoDB must be encrypted at rest. Furthermore, the encryption keys must be rotated automatically on an annual basis to enhance security posture. Which DynamoDB encryption configuration meets these requirements with minimal operational overhead for key management?
- ADynamoDB encryption at rest using customer managed keys (CMKs) with manual key rotation.
- BDynamoDB encryption at rest using AWS owned keys.
- CDynamoDB encryption at rest using a KMS Custom Key Store backed by AWS CloudHSM.
- DDynamoDB encryption at rest using AWS managed keys (AWS KMS).
Show answer & explanationAnswer & explanation
Correct answer: D. DynamoDB encryption at rest using AWS managed keys (AWS KMS).
DynamoDB encryption at rest with AWS managed keys in AWS KMS provides encryption and automatic annual key rotation with minimal operational overhead, as AWS handles the key management and rotation process.
Why the other options are wrong
- A. Customer managed keys (CMKs) allow for automatic rotation, but the question specifies 'minimal operational overhead for key management.' While automatic rotation can be enabled for CMKs, AWS managed keys simplify this further as AWS handles the CMK creation and initial setup.
- B. AWS owned keys are rotated by AWS, but this option does not explicitly offer the customer control over rotation frequency or visibility into the rotation schedule.
- C. A KMS Custom Key Store with CloudHSM adds significant operational overhead (managing CloudHSM clusters) and is not necessary for basic automatic annual key rotation.
DynamoDB Encryption with AWS Managed Keys (KMS)
Amazon DynamoDB encryption at rest with AWS managed keys uses AWS Key Management Service (KMS) to encrypt table data, providing automatic annual key rotation and minimal operational overhead for key management.
- Encryption keys are managed by AWS KMS on the customer's behalf.
- Automatically rotates annually without customer intervention.
- Provides encryption at rest for DynamoDB tables.
- Lower operational overhead compared to customer-managed keys.
Memory trick: AWS-Managed Keys Make DynamoDB Data Secure and Simple.