AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium

A developer is building an application that needs to store confidential user data, such as personally identifiable information (PII), in an Amazon S3 bucket. The data must be encrypted at rest, and the encryption keys must be managed by the developer, with full audit control over key usage. Which S3 encryption option should the developer choose?

  1. AServer-Side Encryption with KMS Keys (SSE-KMS)
  2. BServer-Side Encryption with Customer-Provided Keys (SSE-C)
  3. CClient-Side Encryption
  4. DServer-Side Encryption with S3-Managed Keys (SSE-S3)
Show answer & explanation

Correct answer: A. Server-Side Encryption with KMS Keys (SSE-KMS)

Server-Side Encryption with KMS keys (SSE-KMS) allows S3 to encrypt objects using AWS KMS customer master keys (CMKs). This option gives the developer control over the CMKs, including key rotation and audit trails via AWS CloudTrail, meeting the requirements for developer-managed keys and audit control.

Why the other options are wrong

  • B. SSE-C requires the developer to provide and manage their own encryption keys for each object, which is more complex and doesn't leverage AWS KMS for auditability.
  • C. Client-Side Encryption encrypts data before sending it to S3, but the question specifies server-side encryption with developer-managed keys, and SSE-KMS offers better integration with audit trails.
  • D. SSE-S3 uses S3-managed keys, which does not provide the developer with control over key usage or audit trails.

S3 Server-Side Encryption with KMS (SSE-KMS)

S3 server-side encryption with AWS KMS keys (SSE-KMS) protects your data at rest by encrypting each object with a unique key, which is then encrypted by a master key you manage in AWS KMS.

  • Data encrypted at rest in S3.
  • Uses AWS KMS Customer Master Keys (CMKs).
  • Provides audit trail of key usage via CloudTrail.

Memory trick: For S3 encryption, KMS keys give you full key control and audit permission.

More Development with AWS Services questions