AWS Certified Security – SpecialtyDomain 5: Data ProtectionEasy

A company stores application logs in Amazon CloudWatch Logs. Due to compliance requirements, these logs must be encrypted at rest. The company requires that the encryption keys be managed by AWS Key Management Service (KMS) with customer control over key access policies and auditability through CloudTrail. How can the security engineer ensure that CloudWatch Logs are encrypted with customer-managed KMS keys?

  1. ACloudWatch Logs encrypts all log data with SSE-S3 by default, so no further action is needed.
  2. BSpecify the KMS key ARN when creating or updating the CloudWatch Log Group using the `kmsKeyId` parameter.
  3. CConfigure an IAM policy on the log group to enforce encryption with a specified KMS key ARN.
  4. DEnable default encryption for CloudWatch Logs in the AWS account settings, then select the desired KMS key.
Show answer & explanation

Correct answer: B. Specify the KMS key ARN when creating or updating the CloudWatch Log Group using the `kmsKeyId` parameter.

To encrypt CloudWatch Logs with a customer-managed KMS key, you must specify the `kmsKeyId` parameter when creating or updating the CloudWatch Log Group. This explicitly links the log group to a specific KMS Customer Master Key (CMK), allowing customer control over key access and providing auditability via CloudTrail.

Why the other options are wrong

  • A. While CloudWatch Logs provides encryption at rest, it uses AWS-managed keys by default. SSE-S3 is an S3-specific encryption option and not directly applicable to CloudWatch Logs.
  • C. IAM policies control permissions for principals, but they don't configure resource properties like encryption keys for CloudWatch Log Groups. The encryption key is a property of the log group itself.
  • D. AWS does not currently offer a general 'default encryption' setting for CloudWatch Logs at the account level that would allow selecting a custom KMS key for all new log groups. Encryption must be configured per log group.

CloudWatch Logs KMS Encryption

Amazon CloudWatch Logs can encrypt log data at rest using AWS Key Management Service (KMS). This allows customers to use their own Customer Master Keys (CMKs) to encrypt log groups, providing control over key access and auditability.

  • Configured per CloudWatch Log Group.
  • Requires specifying `kmsKeyId` during creation or update.
  • Leverages KMS for key management and audit trails.
  • Default encryption uses AWS-managed keys.

Memory trick: To encrypt logs, 'Key' the 'Log Group' with KMS.

More Domain 5: Data Protection questions