AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium

A global pharmaceutical company is building a new data lake on AWS using Amazon S3. The data lake will store highly sensitive genomic research data, patient records, and clinical trial results. The company requires that all data at rest be encrypted with customer-managed keys (CMKs) and that the encryption keys never leave the AWS Key Management Service (KMS) boundary, even during cryptographic operations. They also need to ensure that different research teams can manage their own encryption keys for their specific datasets while still adhering to the central security policy. Which data encryption solution best meets these requirements?

  1. AServer-Side Encryption with AWS KMS (SSE-KMS) using separate CMKs for each research team.
  2. BServer-Side Encryption with S3-managed encryption keys (SSE-S3).
  3. CClient-Side Encryption (CSE) using a client-side master key stored in an external Hardware Security Module (HSM).
  4. DServer-Side Encryption with KMS Custom Key Store backed by AWS CloudHSM.
Show answer & explanation

Correct answer: A. Server-Side Encryption with AWS KMS (SSE-KMS) using separate CMKs for each research team.

SSE-KMS allows the use of customer-managed keys (CMKs) for encryption, ensuring keys never leave KMS. Separate CMKs can be created for each team to provide granular control while remaining within KMS.

Why the other options are wrong

  • B. SSE-S3 uses AWS-managed keys, not customer-managed keys, and does not provide granular control for different teams.
  • C. Client-Side Encryption with an external HSM would mean keys are managed outside of KMS, which contradicts the requirement for keys to stay within the KMS boundary.
  • D. While KMS Custom Key Store backed by CloudHSM offers high security, it's typically for scenarios requiring FIPS 140-2 Level 3 validation or existing HSM migration, and doesn't inherently provide the 'separate CMKs for each team' management structure as simply as standard SSE-KMS.

SSE-KMS for Multi-Team Data Encryption

Server-Side Encryption with AWS KMS (SSE-KMS) allows Amazon S3 to encrypt objects using customer-managed keys (CMKs) within AWS KMS, enabling centralized key management and granular access control.

  • Uses customer-managed keys (CMKs) stored in AWS KMS.
  • Keys never leave the KMS service boundary.
  • Supports separate CMKs for different applications or teams, enabling fine-grained security and compliance.

Memory trick: KMS Keys Keep S3 Securely Separate for Each Squad.

More Domain 5: Data Protection questions