A developer is building a serverless application that processes sensitive user data. The application uses AWS Lambda functions and stores data in Amazon S3. To meet compliance requirements, all data at rest in S3 must be encrypted using a customer-managed key (CMK) from AWS Key Management Service (KMS). How can the developer ensure that all objects uploaded to a specific S3 bucket are encrypted using the desired KMS CMK, and prevent unencrypted uploads?
- AConfigure the Lambda function to use `ServerSideEncryptionS3Key` for all S3 `PutObject` calls.
- BAttach a bucket policy that denies `s3:PutObject` requests if `x-amz-server-side-encryption-aws-kms-key-id` is not present.
- CUse S3 event notifications to trigger a Lambda function that encrypts newly uploaded unencrypted objects.
- DEnable default encryption on the S3 bucket using the specified KMS CMK.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable default encryption on the S3 bucket using the specified KMS CMK.
Enabling default encryption on an S3 bucket with a specified AWS KMS CMK is the most straightforward and robust way to ensure all new objects are encrypted with that key. This setting automatically applies the encryption configuration to all new uploads, and optionally, a bucket policy can be added to explicitly deny unencrypted uploads for an extra layer of enforcement.
Why the other options are wrong
- A. While possible, relying on the Lambda function to explicitly specify encryption headers for every upload is prone to human error and doesn't enforce the policy at the bucket level, leaving a window for unencrypted uploads from other sources.
- B. While a bucket policy denying `PutObject` without the `x-amz-server-side-encryption-aws-kms-key-id` header is a strong enforcement mechanism, it's typically used *in conjunction with* default encryption. Default encryption is simpler and automatically handles the encryption for all uploads, making it the primary mechanism, with the policy as a safeguard.
- C. Using S3 event notifications and a Lambda function to encrypt objects post-upload introduces a window where data is unencrypted, which might violate strict compliance requirements. It's also more complex and less efficient than enforcing encryption at the point of upload.
S3 Default Encryption with KMS CMK
Amazon S3 default encryption allows you to configure a bucket to automatically encrypt all new objects uploaded to it using a specified server-side encryption method, including AWS KMS with a Customer Managed Key (CMK), ensuring data-at-rest compliance without requiring client-side configuration.
- Automatically encrypts new objects on upload.
- Can specify AWS KMS CMK for encryption.
- Simplifies client-side code (no need for `x-amz-server-side-encryption` header).
- Can be combined with bucket policies for strict enforcement.
- Ensures compliance for data at rest.
Memory trick: Default 'Encryption' with KMS 'Ensures' S3 'Security'.