AWS Certified Security – SpecialtyDomain 5: Data ProtectionEasy

A global healthcare provider stores vast amounts of patient health information (PHI) in an Amazon S3 bucket. Due to strict regulatory requirements, all PHI data must be encrypted at rest. The security team requires that encryption keys be automatically rotated at least annually and that all key usage be auditable. The solution must also be cost-effective and easy to manage with minimal operational overhead. Which encryption method best meets these requirements?

  1. AClient-Side Encryption with the AWS Encryption SDK
  2. BServer-Side Encryption with S3-managed encryption keys (SSE-S3)
  3. CServer-Side Encryption with AWS Key Management Service (SSE-KMS)
  4. DServer-Side Encryption with Customer-Provided Keys (SSE-C)
Show answer & explanation

Correct answer: C. Server-Side Encryption with AWS Key Management Service (SSE-KMS)

SSE-KMS uses AWS KMS Customer Master Keys (CMKs) which can be configured for automatic annual rotation. All KMS key usage is logged in AWS CloudTrail, providing an audit trail. It is also a managed service, reducing operational overhead compared to client-side encryption.

Why the other options are wrong

  • A. Client-side encryption requires the customer to manage key storage, rotation, and the encryption process, increasing operational overhead and not meeting the automatic rotation requirement for AWS-managed keys.
  • B. SSE-S3 uses S3-managed keys that are automatically rotated by S3, but it does not provide an audit trail of key usage in CloudTrail, which is a key requirement.
  • D. SSE-C requires the customer to manage and rotate their own encryption keys, which does not meet the automatic rotation or ease of management requirements.

SSE-KMS Benefits

Server-Side Encryption with AWS KMS provides encryption at rest for S3 objects using KMS-managed keys, offering automatic key rotation, auditability, and integration with AWS services.

  • Uses AWS KMS Customer Master Keys (CMKs)
  • Supports automatic annual key rotation
  • Key usage is logged in AWS CloudTrail for auditability
  • Managed service, reducing operational burden

Memory trick: KMS: Keys Managed Securely, Audited Regularly.

More Domain 5: Data Protection questions