AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium
A healthcare provider stores sensitive patient health information (PHI) in an Amazon S3 bucket. The company needs to implement a solution to ensure that all objects uploaded to this S3 bucket are encrypted at rest using encryption keys that they manage, and that all access to these encryption keys is centrally audited. Which S3 encryption option should be chosen?
- AServer-Side Encryption with AWS Key Management Service (SSE-KMS).
- BServer-Side Encryption with Amazon S3-managed keys (SSE-S3).
- CClient-side encryption using a custom encryption library.
- DServer-Side Encryption with Customer-Provided Keys (SSE-C).
Show answer & explanationAnswer & explanation
Correct answer: A. Server-Side Encryption with AWS Key Management Service (SSE-KMS).
SSE-KMS uses AWS KMS Customer Master Keys (CMKs) which are managed by the customer. This meets the requirement for customer-managed encryption keys. Additionally, AWS KMS integrates with AWS CloudTrail, providing a central audit trail of all API calls made to KMS, including key usage for encryption and decryption, satisfying the auditing requirement.
Why the other options are wrong
- B. SSE-S3 uses keys managed by AWS, not the customer, failing the 'customer-managed encryption keys' requirement.
- C. Client-side encryption requires a custom solution for key management and auditing, which is more complex than leveraging native AWS KMS auditing for 'encryption at rest' in S3.
- D. SSE-C uses customer-provided keys but doesn't offer the centralized auditing capabilities of KMS for key usage.
SSE-KMS for Central Key Management & Audit
Server-Side Encryption with AWS Key Management Service (SSE-KMS) allows customers to use their own AWS KMS Customer Master Keys (CMKs) for encrypting data at rest and provides a central audit trail of key usage through AWS CloudTrail.
- Uses customer-managed CMKs in AWS KMS.
- Integrates with CloudTrail for auditing key usage.
- Provides granular access control for CMKs via IAM policies.
Memory trick: KMS keys for S3, audited centrally, easy to see.