AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium
A financial services company is migrating its on-premises applications to AWS. They have a strict compliance requirement that all data stored in Amazon EBS volumes attached to their EC2 instances must be encrypted by default, without requiring manual intervention from developers. This encryption must use customer-managed keys (CMKs) from AWS Key Management Service (KMS) for enhanced control and auditing. How can this be enforced across their AWS account?
- AApply an IAM policy to all IAM users and roles, denying the creation of unencrypted EBS volumes.
- BEnable default encryption for all S3 buckets in the account and configure EBS to use S3 for storage.
- CUse AWS Config rules to detect unencrypted EBS volumes and remediate them automatically.
- DEnable default encryption for EBS in the EC2 settings for each region and specify a custom KMS key.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable default encryption for EBS in the EC2 settings for each region and specify a custom KMS key.
Enabling default encryption for EBS in the EC2 settings for each region ensures that all newly created EBS volumes are encrypted automatically. Specifying a custom KMS key fulfills the requirement for customer-managed keys (CMKs) and enhanced control.
Why the other options are wrong
- A. While IAM policies can restrict actions, enforcing default encryption with a specific KMS key is better handled by the EC2 default encryption setting, rather than relying solely on denial policies.
- B. EBS volumes do not use S3 for storage; they are block storage. This option is fundamentally incorrect.
- C. AWS Config can detect and potentially remediate, but it's a reactive control. The requirement is for encryption 'by default' without manual intervention, implying a proactive enforcement.
EBS Default Encryption
You can enable default encryption for all new EBS volumes and snapshot copies created in a specific AWS Region for your account, using either AWS-managed or customer-managed KMS keys.
- Applied per AWS Region.
- Affects newly created volumes and snapshot copies.
- Can use AWS-managed keys or customer-managed (CMK) keys.
- Enforces encryption without manual intervention.
Memory trick: EBS Encryption is Enabled Easily by Default.