AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A global pharmaceutical company is developing a new data analytics platform that processes highly sensitive patient genomic data. This data is stored in Amazon S3. The company has a strict regulatory requirement that all encryption keys for sensitive data must be generated and managed within their on-premises Hardware Security Modules (HSMs) and never leave the HSM boundary. The solution must integrate seamlessly with AWS services for data processing and storage, without compromising the on-premises key management policy. Which AWS data protection solution should the company implement?

  1. AImplement client-side encryption using a customer-managed encryption library to encrypt data with keys generated and managed by the on-premises HSMs before uploading to Amazon S3.
  2. BConfigure Server-Side Encryption with Amazon S3-managed keys (SSE-S3) and use an S3 bucket policy to restrict access to authorized IAM roles.
  3. CUse Server-Side Encryption with AWS Key Management Service (SSE-KMS) and import key material from the on-premises HSMs into KMS custom key stores.
  4. DUtilize Server-Side Encryption with Customer-Provided Keys (SSE-C) by generating keys in the on-premises HSMs and providing them with each S3 API request.
Show answer & explanation

Correct answer: A. Implement client-side encryption using a customer-managed encryption library to encrypt data with keys generated and managed by the on-premises HSMs before uploading to Amazon S3.

Client-side encryption with keys managed by on-premises HSMs ensures that the encryption keys never leave the customer's control, meeting the strict regulatory requirement. The data is encrypted before it ever reaches AWS, thus the keys are not exposed to AWS KMS or other AWS services.

Why the other options are wrong

  • B. SSE-S3 uses AWS-managed keys, which does not meet the requirement for keys to be generated and managed within on-premises HSMs.
  • C. Importing key material into KMS custom key stores means the key material eventually resides in AWS KMS, which violates the requirement that keys never leave the on-premises HSM boundary.
  • D. While SSE-C uses customer-provided keys, these keys must be provided with each API request to S3. This implies the keys are temporarily exposed to the S3 service during the request, which might not fully comply with the 'never leave HSM boundary' for the key itself, only its use. Client-side encryption is a stronger guarantee for key residency.

Client-Side Encryption with On-Premises HSMs

Encrypting data before sending it to a cloud service using keys generated and managed entirely within the customer's on-premises Hardware Security Modules (HSMs), ensuring keys never leave the customer's control.

  • Data is encrypted locally before upload.
  • Encryption keys are managed outside of AWS.
  • Provides the highest level of key control and data sovereignty.

Memory trick: To keep keys truly home, encrypt before you roam.

More Domain 5: Data Protection questions