AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityEasy

A security architect needs to ensure that all newly created Amazon EBS volumes within a specific AWS account are encrypted by default. This is a mandatory compliance requirement for all data at rest. The architect wants to implement a solution that automatically enforces encryption without requiring manual intervention from developers. Which configuration should the architect implement?

  1. ASet the default encryption for EBS in the AWS account to 'enabled'.
  2. BUse a custom Lambda function triggered by CloudWatch Events to encrypt newly created unencrypted EBS volumes.
  3. CImplement an IAM policy that denies the creation of unencrypted EBS volumes.
  4. DCreate an AWS Config rule to detect unencrypted EBS volumes and remediate them by attaching KMS keys.
Show answer & explanation

Correct answer: A. Set the default encryption for EBS in the AWS account to 'enabled'.

Enabling default encryption for EBS in the AWS account settings is the simplest and most direct way to ensure that all newly created EBS volumes are encrypted automatically. This setting applies to all EBS volumes created in that region for the account and does not require manual intervention or additional services for enforcement.

Why the other options are wrong

  • B. A custom Lambda function is a reactive and more complex solution. It adds operational overhead and might have a delay, potentially leaving volumes unencrypted for a short period.
  • C. While an IAM policy can deny creation, it's a reactive measure that blocks developer actions. Enabling default encryption is a proactive, seamless solution.
  • D. An AWS Config rule can detect non-compliance, but remediation might be complex and reactive. It's better to prevent unencrypted volumes from being created in the first place.

Default EBS Encryption

AWS allows you to enable default encryption for all newly created Amazon EBS volumes and snapshot copies in a specific AWS Region for your account. Once enabled, all new EBS volumes created in that Region are automatically encrypted.

  • Applies to new EBS volumes and snapshot copies in a specific region.
  • Uses the default KMS key for EBS or a specified custom KMS key.
  • A simple, proactive way to enforce encryption at rest.
  • Does not affect existing unencrypted volumes.

Memory trick: To encrypt all EBS, just 'flip the default switch' in the account settings.

More Domain 3: Infrastructure Security questions