AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data must be logically separated and encrypted with a unique key derived from their individual tenant ID, to meet multi-tenancy isolation requirements and demonstrate strong data segregation. The solution must be scalable and minimize the performance impact on DynamoDB operations. Which encryption strategy should be implemented?

  1. AConfigure DynamoDB encryption at rest using an AWS KMS customer managed key (CMK) for the entire table.
  2. BUtilize DynamoDB encryption at rest with an AWS owned key for the entire table to ensure data is encrypted.
  3. CStore customer data in separate DynamoDB tables, each encrypted with a unique AWS KMS customer managed key (CMK).
  4. DImplement application-level encryption where the application encrypts each item using a unique key derived from the tenant ID before writing to DynamoDB.
Show answer & explanation

Correct answer: D. Implement application-level encryption where the application encrypts each item using a unique key derived from the tenant ID before writing to DynamoDB.

Application-level encryption, where the application uses a unique key (derived from the tenant ID) to encrypt each item before storage, provides the strongest logical separation and isolation required for multi-tenancy. This ensures that even if the underlying DynamoDB encryption is compromised, individual tenant data remains protected by their unique key.

Why the other options are wrong

  • A. Encrypting the entire table with a single CMK does not provide unique key derivation per tenant or logical isolation at the item level. All tenants' data would be encrypted with the same key.
  • B. AWS owned keys provide encryption at rest but offer no customer control or tenant-specific key derivation. This does not meet the requirement for unique key per tenant.
  • C. While separate tables provide strong physical separation, it can lead to significant operational complexity and cost overhead for a large number of tenants. Application-level encryption is more scalable for multi-tenancy with unique keys.

Application-Level Encryption for Multi-Tenancy

Encrypting individual data items within an application using unique, tenant-specific keys before storing them in a shared database, ensuring strong logical separation and isolation for multi-tenant architectures.

  • Provides granular data protection per tenant.
  • Keys are derived or managed per tenant, not per database or table.
  • Offers stronger isolation than database-level encryption for multi-tenant data segregation.
  • Requires application code changes for encryption/decryption.

Memory trick: App-Level Keys Isolate Tenants.

More Domain 5: Data Protection questions