AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is implementing an application that processes highly confidential customer data. This data is stored in an Amazon S3 bucket. The security team requires that all data stored in this S3 bucket must be encrypted at rest using a customer-provided encryption key (SSE-C) to ensure that AWS does not store or manage the encryption keys. How should the developer configure the application to ensure SSE-C is used for all objects uploaded to the S3 bucket?
- AConfigure the S3 bucket policy to enforce server-side encryption with AWS KMS (SSE-KMS).
- BUse an S3 lifecycle policy to transition objects to an encrypted state after upload.
- CEnable default encryption for the S3 bucket using an AWS-managed key (SSE-S3).
- DInclude the `x-amz-server-side-encryption-customer-key` header with a base64-encoded AES-256 key in every PUT request.
Show answer & explanationAnswer & explanation
Correct answer: D. Include the `x-amz-server-side-encryption-customer-key` header with a base64-encoded AES-256 key in every PUT request.
To use SSE-C, the application must provide the customer-provided encryption key in specific HTTP headers for every PUT (upload) request. S3 then uses this key to encrypt the object and discards the key after encryption. The same key must be provided for GET (download) requests.
Why the other options are wrong
- A. SSE-KMS uses AWS KMS to manage keys, which contradicts the requirement of the customer providing and managing the key.
- B. Lifecycle policies are for managing object transitions and expirations, not for enforcing SSE-C during the initial upload.
- C. SSE-S3 uses AWS-managed keys, not customer-provided keys.
Amazon S3 Server-Side Encryption with Customer-Provided Keys (SSE-C)
SSE-C allows you to encrypt S3 objects using an encryption key that you provide. Amazon S3 manages the encryption and decryption process, but you manage the encryption key. AWS does not store your key.
- You manage the encryption key.
- Key must be provided with every PUT and GET request.
- AWS encrypts/decrypts but does not store the key.
- Requires HTTP headers: `x-amz-server-side-encryption-customer-key` and `x-amz-server-side-encryption-customer-key-MD5`.
Memory trick: SSE-C: Your Key, Your Rules, Every Request.