AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityEasy

A company requires that all data stored in Amazon EBS volumes attached to their EC2 instances must be encrypted. They also need to ensure that the encryption keys are managed by AWS Key Management Service (KMS) and that the encryption is enforced by default for all new volumes. What is the most effective way to implement this requirement?

  1. AUse a custom AMI with encrypted root volumes and enforce encryption at launch time.
  2. BAttach an IAM policy to EC2 instances that forces EBS volumes to be encrypted.
  3. CEnable default EBS encryption for the AWS account using KMS, and ensure all new volumes are created within that account.
  4. DManually select KMS encryption for each new EBS volume created.
Show answer & explanation

Correct answer: C. Enable default EBS encryption for the AWS account using KMS, and ensure all new volumes are created within that account.

Enabling default EBS encryption for the AWS account, configured to use a specified KMS key, ensures that all new EBS volumes and snapshot copies created within that account are automatically encrypted by default. This is the most effective and least operational overhead method for enforcing encryption.

Why the other options are wrong

  • A. While using custom AMIs with encrypted root volumes is good, it only covers root volumes and doesn't enforce encryption for additional data volumes attached later, nor does it set encryption as a default for all new volumes created independently.
  • B. IAM policies can restrict actions (e.g., prevent creating unencrypted volumes), but they don't *enforce* default encryption. The default EBS encryption setting is the direct mechanism for this.
  • D. Manually selecting encryption for each volume is prone to human error and does not enforce encryption by default, making it inefficient and unreliable for compliance.

Default EBS Encryption

An account-level setting in AWS that automatically encrypts all new Amazon EBS volumes and snapshot copies created within that account using AWS KMS.

  • Account-wide setting.
  • Applies to all new EBS volumes and snapshot copies.
  • Uses AWS KMS for key management.
  • Simplifies compliance and reduces operational overhead.

Memory trick: EBS Default: Encrypt All with KMS!

More Domain 3: Infrastructure Security questions