AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium

A global technology company is developing a new serverless application that processes highly sensitive customer personal data. The application uses AWS Lambda functions to process data and stores it in Amazon RDS for PostgreSQL. The company has a strict data residency requirement that mandates all data, including backups and snapshots, must remain within a specific AWS Region. Which solution ensures that the data at rest, including backups and snapshots, adheres to this data residency requirement?

  1. AImplement application-level encryption for all sensitive data before storing it in Amazon RDS, and ensure that the encryption keys are managed within the required AWS Region.
  2. BEnable encryption at rest for the Amazon RDS instance using an AWS Key Management Service (AWS KMS) customer managed key (CMK) created in the specific AWS Region, and configure automated backups.
  3. CUtilize AWS Backup to create a backup plan that specifies the Amazon RDS instance as the resource and defines a backup vault located within the required AWS Region.
  4. DConfigure automatic backups for the Amazon RDS instance with a backup retention period of 7 days, and ensure that the RDS instance is launched in the required AWS Region.
Show answer & explanation

Correct answer: B. Enable encryption at rest for the Amazon RDS instance using an AWS Key Management Service (AWS KMS) customer managed key (CMK) created in the specific AWS Region, and configure automated backups.

To ensure data residency for RDS, including backups and snapshots, encryption at rest using a KMS key from the specific region is critical. RDS backups and snapshots inherit the encryption configuration of the source instance, meaning if the instance is encrypted with a regional KMS key, its backups will also be encrypted with that same key and remain within that region.

Why the other options are wrong

  • A. Application-level encryption protects the data itself but does not inherently manage the residency of the underlying database backups and snapshots created by AWS services. The RDS service still creates backups of the encrypted blobs, and their residency depends on RDS's configuration.
  • C. AWS Backup can create backups in a specific region, but without encryption tied to a regional KMS key, there's a potential for metadata or other aspects of the backup process to cross regional boundaries, or for the backup itself to be copied to another region.
  • D. While launching the RDS instance in the correct region covers the primary data, it does not explicitly guarantee that backups and snapshots will not be replicated or managed outside that region without proper encryption and key management.

RDS Data Residency with KMS

Ensuring Amazon RDS data, including backups and snapshots, remains within a specific AWS Region by encrypting the instance with an AWS KMS customer managed key created in that region.

  • RDS backups and snapshots inherit the encryption settings of the source instance.
  • KMS keys are regional, binding data encrypted with them to that region.
  • CMKs provide explicit control over key management and regional placement.

Memory trick: Keys Lock Data to Regions.

More Domain 5: Data Protection questions