AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is designing a microservices architecture where services communicate asynchronously via Amazon SQS. Sensitive customer data will be transmitted through these SQS queues. The security team requires that all messages in transit and at rest within SQS must be encrypted. Furthermore, the encryption keys must be centrally managed and auditable. Which SQS encryption option should the developer implement?
- AServer-Side Encryption (SSE) using SQS-managed encryption keys
- BClient-Side Encryption with application-managed keys
- CEncrypt messages manually before sending to SQS and decrypt after receiving.
- DServer-Side Encryption (SSE) using AWS Key Management Service (KMS) customer master keys (CMKs)
Show answer & explanationAnswer & explanation
Correct answer: D. Server-Side Encryption (SSE) using AWS Key Management Service (KMS) customer master keys (CMKs)
Server-Side Encryption (SSE) using AWS KMS CMKs for SQS ensures that messages are encrypted at rest and in transit (within SQS's control plane). KMS CMKs are centrally managed and their usage is auditable via AWS CloudTrail, satisfying all the security team's requirements.
Why the other options are wrong
- A. SSE with SQS-managed keys does not allow for customer management or auditing of the encryption keys.
- B. Client-side encryption requires manual management of keys and encryption/decryption logic, which is not centrally managed by AWS.
- C. Manually encrypting/decrypting messages is prone to errors, lacks central key management, and doesn't leverage SQS's native encryption features for at-rest encryption within the service.
SQS Server-Side Encryption (SSE-KMS)
Encrypts messages at rest within Amazon SQS queues using AWS Key Management Service (KMS) customer master keys (CMKs). This provides central management and auditing capabilities for the encryption keys.
- Encrypts messages at rest in SQS
- Uses AWS KMS CMKs for encryption
- Provides auditable key usage via CloudTrail
Memory trick: SQS talks securely with KMS keys.