AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium

A healthcare provider stores sensitive patient health information (PHI) in an Amazon S3 bucket. Due to compliance requirements (e.g., HIPAA), all PHI must be encrypted at rest, and there must be a detailed audit trail of all key usage. The security team wants to manage the encryption keys and their policies directly. Which S3 encryption option best meets these requirements?

  1. AServer-Side Encryption with customer-provided encryption keys (SSE-C).
  2. BClient-Side Encryption (CSE) with a customer-provided encryption key (CSE-C).
  3. CServer-Side Encryption with AWS Key Management Service (SSE-KMS).
  4. DServer-Side Encryption with S3-managed encryption keys (SSE-S3).
Show answer & explanation

Correct answer: C. Server-Side Encryption with AWS Key Management Service (SSE-KMS).

SSE-KMS uses AWS KMS for key management, which provides customer-managed keys, detailed audit trails via CloudTrail, and allows the security team to define key policies, directly meeting all requirements.

Why the other options are wrong

  • A. SSE-C requires the customer to provide and manage the keys on their own, and S3 does not store these keys, making detailed key usage audit trails challenging to implement and manage directly via AWS services.
  • B. CSE-C requires the client application to manage encryption and keys, which can be complex and doesn't inherently provide a centralized audit trail of key usage through AWS services.
  • D. SSE-S3 uses AWS-managed keys, not customer-managed keys, and does not provide a detailed audit trail of key usage for the customer.

SSE-KMS for Compliance

Server-Side Encryption with AWS KMS (SSE-KMS) for Amazon S3 automatically encrypts objects using customer-managed keys (CMKs) in AWS KMS, providing a robust solution for compliance, auditing, and key management.

  • Uses customer-managed keys (CMKs) stored and managed in AWS KMS.
  • Integrates with AWS CloudTrail to provide detailed audit logs of all key usage.
  • Allows security teams to define granular key policies and access controls for CMKs.

Memory trick: KMS Keeps PHI Secure, Compliant, and Key-Controlled.

More Domain 5: Data Protection questions