AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium

A global manufacturing company is migrating its enterprise resource planning (ERP) system to AWS. The ERP system stores highly sensitive intellectual property (IP) and financial data in an Amazon Aurora MySQL-compatible database. The company has a strict compliance requirement that mandates the use of hardware security modules (HSMs) for cryptographic operations and key storage. They also need to retain full control over the cryptographic keys. Which solution meets these requirements for encryption at rest for the Aurora database?

  1. AEncrypt the underlying Amazon EBS volumes attached to the Aurora instances using a dedicated KMS CMK.
  2. BUtilize AWS Key Management Service (AWS KMS) Custom Key Store backed by AWS CloudHSM.
  3. CConfigure Aurora encryption at rest using AWS Key Management Service (AWS KMS) with a customer managed key (CMK).
  4. DImplement client-side encryption within the ERP application before storing data in Aurora, using an on-premises HSM.
Show answer & explanation

Correct answer: B. Utilize AWS Key Management Service (AWS KMS) Custom Key Store backed by AWS CloudHSM.

AWS KMS Custom Key Store backed by AWS CloudHSM allows customers to use their own CloudHSM cluster as the backing store for KMS keys. This provides the FIPS 140-2 Level 3 validated hardware security module (HSM) protection and full control over the keys, fulfilling both the HSM mandate and key control requirements for Aurora encryption at rest.

Why the other options are wrong

  • A. Aurora manages its own storage layer, which is not directly exposed as EBS volumes for independent encryption configuration. Aurora has its own encryption at rest settings, which are applied to the cluster volume, not individual EBS volumes.
  • C. While KMS CMKs provide customer control over key policies and usage, the underlying hardware for KMS is not directly accessible or managed by the customer as a dedicated HSM, and it doesn't guarantee FIPS 140-2 Level 3 validation at the customer's direct control.
  • D. Client-side encryption would require significant application changes and would not encrypt the data at rest that Aurora itself manages (e.g., backups, snapshots), nor does it integrate with Aurora's native encryption capabilities.

KMS Custom Key Store with CloudHSM

A feature of AWS KMS that allows customers to use their own AWS CloudHSM cluster as the backing store for their KMS keys, providing FIPS 140-2 Level 3 validated hardware security module (HSM) protection and exclusive control over key material.

  • Integrates CloudHSM with KMS for seamless service integration.
  • Ensures cryptographic operations and key storage occur within customer-controlled HSMs.
  • Meets strict compliance requirements for dedicated hardware security.

Memory trick: CloudHSM is KMS's Custom Strongbox.

More Domain 5: Data Protection questions