AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A company is required to encrypt all data at rest for a new application deployed on Amazon EC2 instances using EBS volumes. The encryption keys must be managed by the company, and the solution must be scalable and easy to implement across multiple instances. Which approach should the SysOps administrator use?

  1. AEncrypt the EBS volumes using a customer-managed key (CMK) in AWS KMS.
  2. BEnable default EBS encryption for the EC2 instance using an AWS-managed key.
  3. CUse instance store volumes with built-in encryption for all data.
  4. DImplement client-side encryption of data before storing it on unencrypted EBS volumes.
Show answer & explanation

Correct answer: A. Encrypt the EBS volumes using a customer-managed key (CMK) in AWS KMS.

The requirement states that 'encryption keys must be managed by the company'. AWS KMS with customer-managed keys (CMKs) allows the company to create, own, and manage their encryption keys. When creating EBS volumes, you can specify a CMK to encrypt them. This ensures that the data at rest on the EBS volumes is encrypted using a key controlled by the company, and it's scalable and easy to implement across multiple instances through launch templates or automation.

Why the other options are wrong

  • B. Enabling default EBS encryption uses an AWS-managed key, which does not meet the requirement for the company to manage the keys.
  • C. Instance store volumes are ephemeral storage and are not suitable for persistent data storage like patient records. While some instance stores support encryption, they are not a replacement for EBS for persistent data, and their keys are typically AWS-managed.
  • D. Client-side encryption adds significant complexity and operational overhead, requiring application-level changes and managing encryption/decryption logic within the application, which is less scalable and harder to implement than leveraging native EBS encryption with KMS.

EBS Encryption with Customer-Managed Keys

Encrypting Amazon EBS volumes using a Customer-Managed Key (CMK) in AWS Key Management Service (KMS) allows the customer to control and manage the encryption keys for data at rest.

  • Encrypts data on EBS volumes at rest.
  • Customer controls the KMS CMK lifecycle.
  • Integrates seamlessly with EC2 and EBS.
  • Ensures compliance with key management requirements.

Memory trick: EBS encryption with CMK: 'E'ncrypt 'B'y 'S'pecifying 'C'ustomer 'M'anaged 'K'ey.

More Security and Compliance questions