AWS Certified Developer – Associate (DVA-C02)SecurityHard

A developer is building a sensitive microservice that processes payment information. This microservice runs on AWS Fargate and needs to store encrypted temporary data at rest on its local storage for processing, which is ephemeral and automatically deleted when the task stops. The data must be encrypted using a customer-managed key (CMK) from AWS KMS. How can the developer ensure this temporary data is encrypted with a CMK?

  1. AMount an Amazon EFS file system encrypted with a KMS CMK to the Fargate task.
  2. BConfigure the Fargate task definition to use an encrypted Amazon EBS volume.
  3. CEnable Fargate's default platform encryption for ephemeral storage.
  4. DImplement client-side encryption within the application before writing to local storage.
Show answer & explanation

Correct answer: D. Implement client-side encryption within the application before writing to local storage.

Fargate's ephemeral storage is not directly configurable for encryption with a specific KMS CMK by default. To ensure encryption with a customer-managed key for temporary local storage, the application itself must perform client-side encryption using the AWS KMS SDK before writing data to that storage.

Why the other options are wrong

  • A. While EFS can be encrypted with KMS CMK, it's a network file system for persistent storage, not the 'local storage' (ephemeral) mentioned for temporary processing data within the Fargate task.
  • B. Fargate tasks do not support attaching Amazon EBS volumes directly; they use ephemeral storage.
  • C. Fargate's default platform encryption uses AWS-managed keys, not customer-managed keys (CMKs) as required.

Fargate Ephemeral Storage Encryption with CMK

AWS Fargate tasks use ephemeral local storage that is not directly configurable for customer-managed key (CMK) encryption. To encrypt data on this storage with a CMK, the application must perform client-side encryption using AWS KMS.

  • Fargate ephemeral storage is deleted when the task stops.
  • Default Fargate encryption uses AWS-managed keys.
  • Client-side encryption is necessary for CMK use on ephemeral storage.

Memory trick: Client-Side Code Secures Fargate's Ephemeral Cache with CMK.

More Security questions