AWS Certified Security – SpecialtyDomain 5: Data ProtectionEasy

A financial institution is migrating its on-premises data to AWS. Due to strict regulatory compliance, all customer data, including personally identifiable information (PII) and financial transaction records, must remain within a specific geographic region (e.g., Frankfurt, Germany) and not leave that region, even for backup or disaster recovery purposes, unless explicitly approved through a separate, highly secure process. This includes data at rest and data in transit. Which AWS service or feature should the security architect primarily leverage to enforce this data residency requirement for S3 buckets storing this sensitive data?

  1. AS3 Bucket Policies with conditions on `aws:RequestedRegion`
  2. BAWS Organizations Service Control Policies (SCPs) with `Deny` statements on `s3:PutObject` outside the region
  3. CS3 Object Lock configured with Governance mode
  4. DAWS Key Management Service (KMS) with multi-Region keys
Show answer & explanation

Correct answer: B. AWS Organizations Service Control Policies (SCPs) with `Deny` statements on `s3:PutObject` outside the region

AWS Organizations Service Control Policies (SCPs) are the most effective way to enforce strict data residency at an organizational level by preventing actions like `s3:PutObject` in regions outside the allowed ones. This ensures that no S3 objects can be created or transferred out of the specified region.

Why the other options are wrong

  • A. S3 Bucket Policies apply only at the bucket level and can be circumvented by creating buckets in other regions or by using other services. While `aws:RequestedRegion` can restrict access to a bucket from certain regions, it doesn't prevent data from being uploaded to a bucket in a different region in the first place.
  • C. S3 Object Lock prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely, addressing immutability, not data residency.
  • D. AWS KMS multi-Region keys are designed for disaster recovery and compliance by allowing keys to be replicated across regions, which is contrary to a strict data residency requirement that prohibits data from leaving a region.

AWS Service Control Policies (SCPs)

SCPs are a type of policy that you can use to manage permissions in your organization. They offer central control over the maximum available permissions for all accounts in your organization, ensuring accounts stay within your organization’s access control guidelines.

  • Apply to all IAM users and roles in affected accounts.
  • Can enforce region restrictions.
  • Do not grant permissions; they filter maximum permissions.

Memory trick: SCPs are like a global border patrol for your AWS data.

More Domain 5: Data Protection questions