AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is building a new application that uses Amazon S3 to store confidential customer data. The security team has mandated that all data stored in S3 must be encrypted at rest, and the encryption keys must be managed by the customer. The solution should also allow the customer to audit the usage of these encryption keys. Which S3 encryption option meets these requirements?
- AServer-Side Encryption with KMS keys (SSE-KMS)
- BServer-Side Encryption with S3-managed keys (SSE-S3)
- CServer-Side Encryption with Customer-Provided Keys (SSE-C)
- DClient-Side Encryption
Show answer & explanationAnswer & explanation
Correct answer: A. Server-Side Encryption with KMS keys (SSE-KMS)
SSE-KMS allows S3 to encrypt objects using keys managed in AWS KMS. This option meets the requirement for customer-managed keys (specifically, CMKs in KMS) and allows auditing of key usage through AWS CloudTrail, providing control over the encryption process.
Why the other options are wrong
- B. SSE-S3 uses S3-managed keys, which are not customer-managed or auditable by the customer.
- C. SSE-C requires the customer to provide and manage the encryption keys client-side, but S3 performs the encryption/decryption. The keys are not stored in KMS, so auditing key usage through KMS is not applicable.
- D. Client-Side Encryption means the customer encrypts data before sending it to S3, but the question implies S3 performs server-side encryption with customer-managed keys and auditing capabilities.
S3 Server-Side Encryption with KMS (SSE-KMS)
Encrypts S3 objects using keys stored and managed in AWS Key Management Service (KMS). This allows customers to have control over the encryption keys and audit their usage.
- Uses AWS KMS Customer Master Keys (CMKs)
- Keys are customer-managed within KMS
- Key usage is auditable via CloudTrail
Memory trick: S3 encryption has key options: S3, KMS, or Customer.