AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A software-as-a-service (SaaS) provider uses Amazon DynamoDB to store customer metadata. Each customer's data is stored in the same DynamoDB table, but strict isolation and encryption at the application layer are required for multi-tenancy. The solution must ensure that each tenant's data is encrypted with a unique key, and that the application handles the encryption and decryption process before data is sent to or retrieved from DynamoDB. Which approach should the security architect recommend?

  1. AConfigure DynamoDB encryption at rest using AWS KMS Customer Master Keys (CMKs) with a separate CMK for each tenant.
  2. BEncrypt data fields using a tenant-specific symmetric encryption algorithm within the application before storing in DynamoDB, managing keys internally.
  3. CUse DynamoDB's default encryption at rest, and implement row-level security policies to restrict tenant access.
  4. DImplement client-side encryption using the AWS Encryption SDK, with each tenant having a unique data key derived from a tenant-specific KMS CMK.
Show answer & explanation

Correct answer: D. Implement client-side encryption using the AWS Encryption SDK, with each tenant having a unique data key derived from a tenant-specific KMS CMK.

Client-side encryption with the AWS Encryption SDK, combined with unique data keys derived from tenant-specific KMS CMKs, provides the strongest application-level encryption for multi-tenancy. This ensures each tenant's data is encrypted with a unique key that only their specific CMK can decrypt, preventing cross-tenant data access even if the DynamoDB table is compromised. The application handles the encryption/decryption, meeting the requirement for encryption at the application layer.

Why the other options are wrong

  • A. DynamoDB encryption at rest encrypts the entire table or partition. While CMKs can be used, this is server-side encryption and does not provide tenant-specific, application-layer encryption with unique keys per tenant data item.
  • B. While this provides application-layer encryption, managing encryption keys internally (without KMS) is complex, less secure, and prone to errors. It lacks the benefits of KMS for key management, rotation, and auditing.
  • C. DynamoDB's default encryption at rest is server-side and does not provide tenant-specific encryption. Row-level security restricts access but does not enforce encryption with unique keys per tenant at the application layer.

Application-Level Encryption for Multi-Tenancy (AWS Encryption SDK)

Application-level encryption for multi-tenancy encrypts each tenant's data with a unique key at the application layer before it's sent to the database, ensuring strong data isolation. The AWS Encryption SDK simplifies this process by integrating with KMS.

  • Encrypts data before it leaves the application
  • Each tenant's data encrypted with a unique key
  • Uses AWS KMS to manage and derive tenant-specific data keys
  • Provides granular control over encryption for multi-tenant isolation

Memory trick: SDK Secures Distinct Keys for Each Tenant.

More Domain 5: Data Protection questions