AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A company is developing a new serverless application that uses AWS Lambda functions to process user-uploaded files stored in an Amazon S3 bucket. The company requires that all data stored in S3 be encrypted at rest, and the encryption keys must be managed by the customer for compliance reasons. Which S3 encryption option should the developer choose to meet these requirements?
- AServer-Side Encryption with S3-Managed Keys (SSE-S3)
- BServer-Side Encryption with AWS KMS Managed Keys (SSE-KMS)
- CServer-Side Encryption with Customer-Provided Keys (SSE-C)
- DClient-Side Encryption
Show answer & explanationAnswer & explanation
Correct answer: B. Server-Side Encryption with AWS KMS Managed Keys (SSE-KMS)
SSE-KMS uses AWS Key Management Service (KMS) to manage the encryption keys. This allows the customer to have control over the key management policies, including who can use the keys and when they can be used, which aligns with the requirement for customer-managed encryption keys for compliance.
Why the other options are wrong
- A. SSE-S3 manages the encryption keys entirely within S3, not by the customer.
- C. SSE-C requires the customer to provide and manage the encryption keys themselves, which typically means storing them outside AWS and passing them with every request, adding operational complexity not implied by 'managed by the customer for compliance reasons'.
- D. Client-side encryption encrypts data before sending it to S3, but the question specifically asks for an S3 encryption option where keys are managed by the customer, implying a server-side solution with KMS.
S3 Encryption with Customer-Managed Keys (SSE-KMS)
Server-Side Encryption with AWS KMS Managed Keys (SSE-KMS) uses AWS KMS to manage the encryption keys for Amazon S3 objects, allowing customers to control key usage policies.
- Encryption keys are managed within AWS KMS.
- Provides an audit trail of key usage in CloudTrail.
- Suitable for compliance requirements needing customer control over keys.
Memory trick: KMS Keys Keep S3 Compliance.