AWS Certified Developer – Associate (DVA-C02)SecurityEasy

A developer is building an application that uses Amazon SQS. Messages sent to the queue contain sensitive customer data. The developer needs to ensure that these messages are encrypted at rest within the SQS queue. Which feature should be enabled to meet this requirement?

  1. AClient-side encryption for SQS messages.
  2. BEnable SQS Access Policies to restrict access to the queue.
  3. CUse a VPC endpoint for SQS to encrypt traffic in transit.
  4. DServer-Side Encryption (SSE) for SQS using AWS KMS.
Show answer & explanation

Correct answer: D. Server-Side Encryption (SSE) for SQS using AWS KMS.

Server-Side Encryption (SSE) for Amazon SQS using AWS KMS is the feature designed to encrypt messages at rest within SQS queues. When enabled, SQS encrypts the message body as soon as it's received and decrypts it when a consumer retrieves it.

Why the other options are wrong

  • A. Client-side encryption encrypts before sending, but SSE handles encryption at rest within the queue itself.
  • B. Access policies control who can access the queue but do not provide encryption for messages at rest.
  • C. VPC endpoints encrypt traffic in transit between the application and SQS, not messages at rest within the queue.

SQS Server-Side Encryption (SSE)

Amazon SQS Server-Side Encryption (SSE) uses AWS Key Management Service (KMS) to encrypt messages at rest within SQS queues.

  • Encrypts message bodies stored in SQS queues.
  • Uses AWS KMS customer master keys (CMKs).
  • Transparent to the client application.

Memory trick: SQS SSE with KMS keeps your messages safe at rest.

More Security questions