AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data must be logically separated and encrypted using a unique encryption key derived from their individual customer ID. This ensures that a compromise of one key does not affect other customers' data. The solution needs to be scalable and efficient for a large number of tenants. Which data protection approach should be used?

  1. ACreate a separate DynamoDB table for each customer, each encrypted with a unique AWS KMS CMK.
  2. BUtilize AWS KMS Multi-Region keys, and encrypt customer data with these keys based on their geographic region.
  3. CImplement application-level encryption where the application encrypts each customer's data using a unique key per customer before writing to DynamoDB.
  4. DUse DynamoDB encryption at rest with a single AWS KMS CMK and apply item-level access control.
Show answer & explanation

Correct answer: C. Implement application-level encryption where the application encrypts each customer's data using a unique key per customer before writing to DynamoDB.

Application-level encryption (also known as client-side encryption for DynamoDB) allows the SaaS application to encrypt each customer's data with a unique key derived from their customer ID before storing it in DynamoDB. This ensures logical separation and tenant-specific key management, providing strong isolation and preventing a single key compromise from affecting other tenants, which is essential for multi-tenancy.

Why the other options are wrong

  • A. Creating a separate DynamoDB table for each customer is not scalable or cost-effective for a large number of tenants, and doesn't explicitly state the key derivation for individual customer IDs.
  • B. Multi-Region keys are for data residency and disaster recovery across regions, not for unique per-tenant encryption within a single application or table.
  • D. A single KMS CMK for all data does not provide unique encryption per customer, failing the 'unique encryption key derived from their individual customer ID' requirement.

Application-Level Encryption for Multi-Tenancy

Encrypting data within a multi-tenant application using keys unique to each tenant (or even per-item per tenant) before storing it in a shared database or storage, ensuring strong logical separation and preventing cross-tenant data compromise.

  • Keys are derived and managed by the application.
  • Provides granular data isolation for multi-tenant architectures.
  • Often implemented client-side before data leaves the application.

Memory trick: Unique IDs, unique keys, secure tenants for all days.

More Domain 5: Data Protection questions