AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium

A global technology company is developing a new serverless application that processes highly sensitive customer data. The data is stored in Amazon DynamoDB. Due to strict compliance requirements, all data in DynamoDB must be encrypted at rest with customer-managed keys (CMKs) that are automatically rotated annually. The security team also requires granular control over who can access and use these encryption keys. Which DynamoDB encryption configuration meets these requirements?

  1. ADynamoDB encryption at rest using AWS owned keys.
  2. BDynamoDB encryption at rest using AWS managed keys (AWS KMS).
  3. CDynamoDB encryption at rest using customer managed keys (CMKs) with automatic key rotation enabled in AWS KMS.
  4. DDynamoDB encryption at rest using a KMS Custom Key Store backed by AWS CloudHSM.
Show answer & explanation

Correct answer: C. DynamoDB encryption at rest using customer managed keys (CMKs) with automatic key rotation enabled in AWS KMS.

DynamoDB encryption at rest with customer-managed keys (CMKs) allows for granular control over key policies and enables automatic annual key rotation via AWS KMS, directly fulfilling all stated requirements.

Why the other options are wrong

  • A. AWS owned keys are not customer-managed, do not offer customer control over key policies, and their rotation is managed by AWS, not the customer.
  • B. AWS managed keys (AWS KMS) are managed by AWS on the customer's behalf; while they use KMS, the customer doesn't have the same level of granular control over key policies as with CMKs, nor can they explicitly enable or disable automatic rotation.
  • D. While a KMS Custom Key Store offers very high security and FIPS 140-2 Level 3 compliance, it's typically for specific regulatory needs beyond standard CMKs and doesn't inherently simplify the 'automatic rotation' or 'granular control' aspects more than a standard CMK in KMS.

DynamoDB Encryption with CMKs & Rotation

Amazon DynamoDB encryption at rest can be configured with customer-managed keys (CMKs) from AWS KMS, allowing customers to control key policies, enable automatic annual key rotation, and meet strict compliance requirements.

  • Uses AWS KMS Customer Master Keys (CMKs) for encryption.
  • CMKs provide granular control over key usage and access policies.
  • Automatic annual key rotation can be enabled for CMKs within AWS KMS.

Memory trick: CMKs Control DynamoDB, Compliantly Rotating Keys.

More Domain 5: Data Protection questions