AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A financial services company is developing a new serverless application using AWS Lambda functions. This application will process highly sensitive customer financial data and store it in an Amazon DynamoDB table. The security team has a strict requirement that all data at rest in DynamoDB must be encrypted using a customer-managed key (CMK) from AWS Key Management Service (KMS) for enhanced control and auditability. How can the developer ensure DynamoDB uses a specific KMS CMK for encryption at rest?

  1. AEnable server-side encryption for DynamoDB and select the desired KMS CMK.
  2. BStore the sensitive data in Amazon S3 and link it to DynamoDB for indexing.
  3. CConfigure the Lambda function to encrypt data before sending it to DynamoDB.
  4. DUse a client-side encryption library within the application to encrypt data.
Show answer & explanation

Correct answer: A. Enable server-side encryption for DynamoDB and select the desired KMS CMK.

DynamoDB supports server-side encryption at rest using AWS KMS. Developers can choose between an AWS owned key (default), an AWS managed key, or a customer managed key (CMK) for their tables, meeting the requirement for enhanced control.

Why the other options are wrong

  • B. This is a workaround for storage, not a direct solution for encrypting data at rest *within* DynamoDB itself using a CMK.
  • C. While possible, this adds complexity and doesn't leverage DynamoDB's native encryption at rest with CMK.
  • D. Client-side encryption is an option, but the requirement is for *data at rest in DynamoDB* to be encrypted with a CMK, which server-side encryption handles natively.

DynamoDB Encryption at Rest

Amazon DynamoDB provides encryption at rest for all tables, protecting sensitive data. You can choose different encryption key types, including AWS owned keys, AWS managed keys, and customer managed keys (CMKs) from AWS KMS.

  • Always encrypted at rest by default.
  • Supports AWS owned, AWS managed, and customer managed KMS keys.
  • Choosing a CMK provides granular control and auditability over the encryption key.

Memory trick: DynamoDB's data rests encrypted, KMS keys its secret keeper.

More Security questions