AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A financial services company is migrating its on-premises data warehouse to Amazon Redshift. Due to strict regulatory compliance, all data at rest in Redshift must be encrypted using customer-managed keys (CMKs) from AWS Key Management Service (KMS). The security team also requires that these CMKs are protected by a FIPS 140-2 Level 3 validated hardware security module (HSM). Which approach meets these requirements?

  1. AUtilize AWS CloudHSM to generate and manage the encryption keys, then integrate with Redshift.
  2. BConfigure Redshift to use a customer-managed KMS key (CMK) and ensure the KMS key is created with the FIPS 140-2 Level 3 option.
  3. CUse Redshift's default encryption with AWS managed keys.
  4. DEncrypt data manually before loading it into Redshift using client-side encryption.
Show answer & explanation

Correct answer: B. Configure Redshift to use a customer-managed KMS key (CMK) and ensure the KMS key is created with the FIPS 140-2 Level 3 option.

AWS KMS CMKs can be configured to use FIPS 140-2 validated HSMs. Redshift can then be configured to use these CMKs for data at rest encryption, satisfying both the customer-managed key and FIPS compliance requirements.

Why the other options are wrong

  • A. While CloudHSM provides FIPS 140-2 Level 3 validated HSMs, integrating it directly with Redshift for data at rest encryption is not the standard or most straightforward approach. KMS provides a managed service that can meet this requirement more easily, as KMS itself uses FIPS-validated HSMs.
  • C. AWS managed keys do not meet the requirement for customer-managed keys (CMKs) and do not explicitly guarantee FIPS 140-2 Level 3 validation for the underlying HSMs.
  • D. Client-side encryption is complex to manage at scale for a data warehouse and does not address the requirement for Redshift data at rest encryption using CMKs directly.

KMS CMKs with FIPS 140-2

AWS Key Management Service (KMS) allows customers to use customer-managed keys (CMKs) for encryption. KMS is designed to be FIPS 140-2 validated, meaning its underlying hardware security modules (HSMs) meet specific security standards, often Level 2, with FIPS endpoints available for Level 3 compliance.

  • CMKs provide customer control over encryption keys.
  • KMS uses FIPS 140-2 validated HSMs.
  • FIPS 140-2 Level 3 offers strong cryptographic protection.
  • Redshift integrates with KMS for data at rest encryption.

Memory trick: Redshift CMK FIPS: Secure Data Warehouse.

More Security and Compliance questions