AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A company is developing an application that requires highly sensitive data to be encrypted both at rest and in transit. For at-rest encryption, they plan to use server-side encryption with customer-provided keys (SSE-C) for objects stored in Amazon S3. For in-transit encryption, they will use SSL/TLS for all communication. What is a key characteristic of SSE-C that the developer must be aware of?

  1. AThe customer is responsible for managing and providing the encryption keys with each S3 API request.
  2. BS3 automatically encrypts objects using an AWS-managed key, with no customer input required.
  3. CAWS KMS manages the encryption keys, and the customer configures S3 to use a specific KMS key.
  4. DAWS manages the encryption keys, and the customer provides them to S3 on each request.
Show answer & explanation

Correct answer: A. The customer is responsible for managing and providing the encryption keys with each S3 API request.

With SSE-C (Server-Side Encryption with Customer-Provided Keys), the customer is entirely responsible for managing the encryption keys. They must provide the encryption key as part of every S3 API request (PUT, GET) that interacts with the encrypted object. S3 uses the key to encrypt/decrypt the object but does not store the key.

Why the other options are wrong

  • B. This describes SSE-S3, not SSE-C.
  • C. This describes SSE-KMS, where AWS KMS manages the keys.
  • D. This is incorrect. The customer manages the keys and provides them, AWS does not manage them in SSE-C.

S3 SSE-C

Server-Side Encryption with Customer-Provided Keys (SSE-C) for Amazon S3 allows customers to provide their own encryption keys for S3 to use during object operations.

  • Customer manages and provides encryption keys.
  • Key must be provided with every PUT and GET request.
  • S3 does not store the customer-provided key.

Memory trick: C for Customer-Provided Keys, K for KMS, S3 for AWS-Managed.

More Security questions