AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium
A financial services company is migrating its on-premises data warehouse to Amazon Redshift. Due to strict regulatory compliance, all data at rest in Redshift must be encrypted using customer-managed keys (CMKs) from AWS Key Management Service (KMS). The security team also requires that these CMKs are protected by a FIPS 140-2 Level 3 validated hardware security module (HSM). Which approach meets these requirements?
- AUtilize AWS CloudHSM to generate and manage the encryption keys, then integrate with Redshift.
- BConfigure Redshift to use a customer-managed KMS key (CMK) and ensure the KMS key is created with the FIPS 140-2 Level 3 option.
- CUse Redshift's default encryption with AWS managed keys.
- DEncrypt data manually before loading it into Redshift using client-side encryption.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure Redshift to use a customer-managed KMS key (CMK) and ensure the KMS key is created with the FIPS 140-2 Level 3 option.
AWS KMS CMKs can be configured to use FIPS 140-2 validated HSMs. Redshift can then be configured to use these CMKs for data at rest encryption, satisfying both the customer-managed key and FIPS compliance requirements.
Why the other options are wrong
- A. While CloudHSM provides FIPS 140-2 Level 3 validated HSMs, integrating it directly with Redshift for data at rest encryption is not the standard or most straightforward approach. KMS provides a managed service that can meet this requirement more easily, as KMS itself uses FIPS-validated HSMs.
- C. AWS managed keys do not meet the requirement for customer-managed keys (CMKs) and do not explicitly guarantee FIPS 140-2 Level 3 validation for the underlying HSMs.
- D. Client-side encryption is complex to manage at scale for a data warehouse and does not address the requirement for Redshift data at rest encryption using CMKs directly.
KMS CMKs with FIPS 140-2
AWS Key Management Service (KMS) allows customers to use customer-managed keys (CMKs) for encryption. KMS is designed to be FIPS 140-2 validated, meaning its underlying hardware security modules (HSMs) meet specific security standards, often Level 2, with FIPS endpoints available for Level 3 compliance.
- CMKs provide customer control over encryption keys.
- KMS uses FIPS 140-2 validated HSMs.
- FIPS 140-2 Level 3 offers strong cryptographic protection.
- Redshift integrates with KMS for data at rest encryption.
Memory trick: Redshift CMK FIPS: Secure Data Warehouse.