AWS Certified Developer – Associate (DVA-C02)SecurityHard

A financial services company is developing a new serverless application using AWS Lambda functions and Amazon DynamoDB. The application will store highly sensitive customer financial data in DynamoDB. The compliance team has mandated that all data at rest in DynamoDB must be encrypted, and the encryption keys must be managed by the customer with full control over key rotation and access policies. Which encryption option should the developer choose for DynamoDB?

  1. ADynamoDB encryption at rest with AWS owned keys
  2. BDynamoDB encryption at rest with AWS managed keys (AWS KMS)
  3. CClient-side encryption before storing data in DynamoDB
  4. DDynamoDB encryption at rest with customer managed keys (AWS KMS)
Show answer & explanation

Correct answer: D. DynamoDB encryption at rest with customer managed keys (AWS KMS)

DynamoDB encryption at rest with customer managed keys (CMKs) in AWS KMS allows the customer to create, own, and manage their encryption keys, including defining key access policies and rotation schedules. This provides the highest level of control and meets the compliance requirement for customer-managed keys with full control.

Why the other options are wrong

  • A. AWS owned keys are fully managed by AWS; the customer has no control over key rotation or access policies.
  • B. AWS managed keys (KMS) are managed by AWS on behalf of the customer, offering some control over key usage but not full control over rotation or granular access policies like CMKs.
  • C. Client-side encryption requires the application to handle encryption/decryption, which adds complexity and may not integrate with DynamoDB's native at-rest encryption or centralized key management/auditing via KMS.

DynamoDB Encryption with Customer Managed Keys (CMK)

DynamoDB encrypts data at rest using Customer Master Keys (CMKs) created and managed by the customer in AWS KMS. This provides the highest level of control over encryption keys, including rotation and access policies.

  • Customer creates and manages CMKs in KMS
  • Full control over key rotation
  • Granular control over key access policies

Memory trick: DynamoDB's key control ranges from AWS to You.

More Security questions