AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A financial services company is developing a new application that processes highly sensitive customer financial data. The company's compliance requirements dictate that data must be encrypted at rest and in transit, and that the encryption keys must be managed by the customer. Furthermore, the solution must prevent any AWS service from automatically decrypting the data on behalf of the customer without explicit customer action or permission. Which encryption solution provides the highest level of customer control and prevents automatic AWS service decryption?

  1. AServer-Side Encryption with Amazon S3-managed keys (SSE-S3)
  2. BServer-Side Encryption with AWS KMS-managed keys (SSE-KMS)
  3. CClient-Side Encryption with a client-managed master key
  4. DServer-Side Encryption with customer-provided keys (SSE-C)
Show answer & explanation

Correct answer: C. Client-Side Encryption with a client-managed master key

Client-Side Encryption with a client-managed master key means the data is encrypted by the customer *before* it is sent to AWS. AWS receives only encrypted data and never has access to the plaintext encryption key. This prevents any AWS service from automatically decrypting the data, as AWS doesn't possess the key required for decryption without the customer explicitly providing it, offering the highest level of customer control.

Why the other options are wrong

  • A. SSE-S3 keys are fully managed by AWS, and AWS services can decrypt data automatically if they have the necessary permissions.
  • B. SSE-KMS keys are managed by KMS, and while customers control the CMK, AWS services (with appropriate IAM permissions to KMS) can request KMS to decrypt data on their behalf. This doesn't prevent *any* AWS service from decrypting without explicit customer action *every time*.
  • D. SSE-C requires the customer to provide the key with each request, giving control. However, the data is decrypted server-side by S3. While S3 doesn't store the key, other AWS services could potentially interact with S3 with the provided key to decrypt, depending on the architecture. It's still server-side decryption.

Client-Side Encryption (CSE)

Client-Side Encryption involves encrypting data on the client's side before it is sent to an AWS service. This ensures that AWS services only ever receive and store ciphertext, and never have access to the plaintext data or the encryption keys.

  • Customer manages all encryption keys and processes.
  • AWS stores only encrypted data.
  • Prevents AWS services from automatic decryption.
  • Highest level of customer control over data privacy.

Memory trick: Encrypt 'Client-Side' to keep AWS 'out of the loop' on your data.

More Domain 5: Data Protection questions