AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A financial institution is migrating its on-premises applications to AWS. Due to strict regulatory requirements, all data at rest on Amazon RDS for PostgreSQL instances must be encrypted. The security team also requires that the encryption keys be centrally managed, automatically rotated annually, and that they have the ability to audit key usage. Which solution meets these requirements with the least operational overhead?

  1. AConfigure Amazon RDS to use customer-managed keys (CMKs) in AWS Key Management Service (KMS).
  2. BConfigure Amazon RDS to use default encryption with AWS-owned keys.
  3. CImplement a custom solution using a third-party key management system integrated with RDS.
  4. DConfigure Amazon RDS to use Server-Side Encryption with customer-provided keys (SSE-C).
Show answer & explanation

Correct answer: A. Configure Amazon RDS to use customer-managed keys (CMKs) in AWS Key Management Service (KMS).

Using customer-managed keys (CMKs) in AWS KMS for RDS encryption allows central management, supports automatic annual key rotation, and provides auditability through CloudTrail logs for key usage. This offers the required control with minimal operational overhead compared to custom or third-party solutions.

Why the other options are wrong

  • B. AWS-owned keys do not offer customer control, auditability of key usage, or explicit annual rotation as required.
  • C. A custom third-party solution would introduce significant operational overhead and complexity, contrary to the 'least operational overhead' requirement.
  • D. SSE-C is for S3, not RDS, and requires the customer to provide and manage keys, which doesn't align with 'centrally managed' and 'least operational overhead' for RDS.

RDS Encryption with KMS CMKs

Amazon RDS encryption with AWS KMS Customer-Managed Keys (CMKs) enables data at rest encryption for database instances, allowing customers to control key lifecycle, rotation, and audit key usage.

  • Encrypts database instances, snapshots, and backups.
  • Leverages AWS KMS for key management.
  • CMKs allow customer control over key policies and rotation.
  • Key usage is auditable via AWS CloudTrail.

Memory trick: RDS Keys: CMK = Control, Managed, Rotated, Auditable.

More Security and Compliance questions