AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium

A healthcare provider stores sensitive patient health information (PHI) in an Amazon S3 bucket. The data must be encrypted at rest and in transit. The security team requires full control over the encryption keys, including the ability to generate, rotate, and revoke them, with an audit trail of all key usage. The solution must also support integration with AWS CloudTrail for logging key operations. Which S3 encryption option best meets these requirements?

  1. AClient-Side Encryption with a client-managed master key
  2. BServer-Side Encryption with AWS KMS-managed keys (SSE-KMS)
  3. CServer-Side Encryption with customer-provided keys (SSE-C)
  4. DServer-Side Encryption with Amazon S3-managed keys (SSE-S3)
Show answer & explanation

Correct answer: B. Server-Side Encryption with AWS KMS-managed keys (SSE-KMS)

SSE-KMS allows customers to use AWS Key Management Service (KMS) for managing encryption keys. This provides full control over key generation, rotation, and revocation, and integrates seamlessly with CloudTrail for auditing key usage, meeting all specified requirements.

Why the other options are wrong

  • A. Client-Side Encryption encrypts data before sending it to S3, but it requires the customer to manage their own encryption library and key storage outside of AWS KMS, which complicates auditing and key lifecycle management compared to SSE-KMS.
  • C. SSE-C requires the customer to provide their own encryption keys with each S3 API request. While it gives customer control, it doesn't offer the integrated key management, rotation, or auditing features of KMS.
  • D. SSE-S3 uses keys managed entirely by AWS. While it encrypts data at rest, it does not provide the customer with control over the keys or an audit trail of key usage in KMS.

Server-Side Encryption with AWS KMS (SSE-KMS)

SSE-KMS uses AWS KMS to manage encryption keys, providing customers with control over key lifecycle and integration with CloudTrail for auditing.

  • Uses customer master keys (CMKs) in KMS.
  • Provides an audit trail of key usage via CloudTrail.
  • Supports automatic key rotation.

Memory trick: KMS gives you the 'Key Master' control for S3 encryption.

More Domain 5: Data Protection questions