AWS Certified Developer – Associate (DVA-C02)SecurityHard

A developer is building a sensitive application that stores user data in an Amazon DynamoDB table. The security team requires that all data stored in the DynamoDB table must be encrypted at rest, and the encryption keys should be managed by the customer with full auditability. Which encryption option for DynamoDB should the developer choose?

  1. ADynamoDB encryption at rest using AWS managed keys (CMK).
  2. BDynamoDB encryption at rest using customer managed keys (CMK).
  3. CDynamoDB encryption at rest using AWS owned keys.
  4. DClient-side encryption of data before writing to DynamoDB.
Show answer & explanation

Correct answer: B. DynamoDB encryption at rest using customer managed keys (CMK).

DynamoDB encryption at rest using customer managed keys (CMK) in AWS KMS provides the highest level of control and auditability. It allows the customer to define key policies, enable/disable keys, and track all key usage through AWS CloudTrail, meeting the requirement for customer management and auditability.

Why the other options are wrong

  • A. AWS managed keys (CMK) are managed by AWS on behalf of the customer, offering some auditability but less control than customer managed keys.
  • C. AWS owned keys are fully managed by AWS and do not provide customer control or auditability over key usage.
  • D. Client-side encryption requires the application to handle encryption/decryption, adding complexity and not leveraging DynamoDB's built-in at-rest encryption features with KMS.

DynamoDB Encryption with Customer Managed Keys (CMK)

DynamoDB encryption at rest using Customer Managed Keys (CMK) in AWS KMS provides customers with granular control, auditability, and management over their encryption keys.

  • Offers the highest level of control over encryption keys.
  • All key operations are logged to CloudTrail for auditability.
  • Customer defines key policies and can enable/disable keys.

Memory trick: CMK gives C-ontrol, M-anagement, K-ey auditability for DynamoDB.

More Security questions