AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is building an application that needs to securely send messages between microservices using Amazon SQS. The messages contain sensitive customer information and must be protected from unauthorized access while in transit and at rest within the queue. The company's security policy dictates that all encryption keys must be rotated automatically and managed by AWS. Which SQS encryption option should the developer choose?

  1. AServer-Side Encryption (SSE) using AWS KMS managed keys (SSE-KMS).
  2. BEncrypt the SQS queue with an AWS Key Management Service (KMS) Customer-Managed Key (CMK).
  3. CServer-Side Encryption (SSE) using SQS-managed encryption keys (SSE-SQS).
  4. DClient-Side Encryption for SQS messages.
Show answer & explanation

Correct answer: C. Server-Side Encryption (SSE) using SQS-managed encryption keys (SSE-SQS).

SSE-SQS uses SQS-managed encryption keys to encrypt messages at rest. These keys are automatically rotated by AWS and transparently handled by SQS, meeting the requirement for AWS-managed keys and automatic rotation without requiring customer intervention or explicit KMS configuration.

Why the other options are wrong

  • A. SSE-KMS uses AWS KMS keys, which can be AWS-managed or customer-managed. While AWS-managed KMS keys are rotated, SSE-SQS is the more direct and simpler option when AWS-managed keys and automatic rotation are explicitly stated as requirements for SQS.
  • B. Using a KMS Customer-Managed Key (CMK) gives the customer more control, but the requirement specifically states 'managed by AWS' and automatically rotated, which SSE-SQS directly fulfills without the overhead of explicit KMS key management.
  • D. Client-side encryption requires the application to manage encryption, which is not what 'keys must be rotated automatically and managed by AWS' implies for SQS.

SQS Server-Side Encryption (SSE-SQS)

SSE-SQS encrypts messages at rest in Amazon SQS queues using SQS-managed encryption keys. These keys are automatically rotated by AWS and offer a fully managed encryption solution.

  • Uses SQS-managed keys.
  • Keys are automatically rotated by AWS.
  • Transparent encryption and decryption for applications.

Memory trick: SQS-Managed Keys Keep Messages Quietly Secure.

More Security questions