AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A global software company is developing a new application that processes highly sensitive customer data. Due to regulatory requirements, all data at rest must be encrypted with keys that are stored and managed outside of AWS for complete customer control and to prevent AWS personnel from accessing the plaintext data. The solution needs to integrate with AWS services like Amazon S3 and Amazon RDS. Which encryption solution meets these stringent requirements?

  1. AUtilize AWS Key Management Service (AWS KMS) Custom Key Store backed by AWS CloudHSM for key generation and storage.
  2. BUse AWS Key Management Service (AWS KMS) with a customer managed key (CMK) and enforce encryption on S3 buckets and RDS instances.
  3. CEncrypt data at the application layer using a FIPS 140-2 Level 3 validated software library and store the keys in an on-premises HSM.
  4. DImplement client-side encryption using a customer-managed external key management system (EKMS) before data is sent to AWS services.
Show answer & explanation

Correct answer: D. Implement client-side encryption using a customer-managed external key management system (EKMS) before data is sent to AWS services.

To meet the requirement of keys being stored and managed *outside* of AWS to prevent AWS personnel from accessing plaintext, client-side encryption with an external key management system is necessary. This ensures that data is encrypted before it ever leaves the customer's environment, and AWS only receives ciphertext.

Why the other options are wrong

  • A. KMS Custom Key Store with CloudHSM stores keys in customer-controlled HSMs *within* AWS. While it offers strong control, the HSMs are still physically located in AWS data centers, and the KMS service itself is an AWS service.
  • B. While KMS CMKs provide control over key policies, the keys themselves are still managed within AWS KMS, and AWS personnel (under specific, rare circumstances, and with customer consent/request) could potentially access plaintext if given access to the KMS service.
  • C. Encrypting at the application layer using an on-premises HSM is a good step, but the question specifies integrating with AWS services like S3 and RDS. Option B (client-side encryption with EKMS) is a broader, more integrated solution for using keys external to AWS for multiple services, potentially via an SDK or proxy, rather than just a standalone application-layer encryption with a specific library.

External Key Management (Client-Side Encryption)

Encrypting data in the client application's environment using keys managed by a system entirely outside of AWS, ensuring that AWS only ever receives and stores ciphertext, providing the highest level of customer control over keys and data privacy.

  • Data is encrypted before it leaves the customer's network.
  • Encryption keys never reside within AWS services.
  • Requires application modification to handle encryption/decryption.
  • Ensures AWS has no access to plaintext data or keys.

Memory trick: External Keys for Ultimate Control.

More Domain 5: Data Protection questions