AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium
A company is required to encrypt all data at rest for a new application deployed on Amazon EC2. The application stores data on Amazon EBS volumes. The security team mandates that the encryption keys must be managed by the customer and automatically rotated annually. Additionally, the keys must be regionally isolated. Which solution should the SysOps administrator implement?
- AUse Server-Side Encryption with customer-provided keys (SSE-C) for the EBS volumes.
- BEnable default EBS encryption for the account and use AWS-managed keys.
- CEncrypt EBS volumes using AWS CloudHSM as a custom key store for KMS.
- DEncrypt EBS volumes using customer-managed keys (CMKs) in AWS KMS, configured for automatic key rotation.
Show answer & explanationAnswer & explanation
Correct answer: D. Encrypt EBS volumes using customer-managed keys (CMKs) in AWS KMS, configured for automatic key rotation.
Encrypting EBS volumes with customer-managed keys (CMKs) in AWS KMS allows the customer to manage the key lifecycle, including enabling automatic annual rotation. CMKs are regional, ensuring regional isolation. This solution directly addresses all requirements.
Why the other options are wrong
- A. SSE-C is for S3, not EBS, and requires the customer to provide and manage the key directly, not through KMS's rotation features.
- B. AWS-managed keys do not provide customer control over key lifecycle or explicit annual rotation, and are not 'customer-managed'.
- C. While CloudHSM provides high security, it adds complexity and is not required for 'customer-managed' and 'automatic rotation' when KMS CMKs suffice. CMKs are already regionally isolated by default.
EBS Encryption with Customer-Managed Keys
Encrypting Amazon EBS volumes using Customer-Managed Keys (CMKs) in AWS KMS provides strong encryption for data at rest, with the customer maintaining full control over the encryption key's lifecycle, policies, and rotation.
- CMKs are created and managed by the customer within KMS.
- Allows configuration of key policies and grants.
- Supports automatic annual key rotation.
- CMKs are regional resources, ensuring regional isolation.
Memory trick: EBS Keys: CMK Gives Control, Rotation, and Region Lock.