AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesEasy

A developer is building an application that needs to store confidential user data, such as personally identifiable information (PII). The data must be encrypted at rest and in transit, and access to the decryption keys must be strictly controlled and audited. Which AWS service combination provides the most secure and compliant solution for storing and managing the encryption keys?

  1. AUse AWS Key Management Service (KMS) to generate and manage customer master keys (CMKs) and encrypt data in Amazon S3.
  2. BStore encryption keys directly in application code and use Amazon S3 for data storage.
  3. CImplement client-side encryption with self-managed keys stored on an Amazon EC2 instance and use Amazon DynamoDB for data storage.
  4. DUse AWS Secrets Manager to store encryption keys and encrypt data using client-side encryption before uploading to Amazon S3.
Show answer & explanation

Correct answer: A. Use AWS Key Management Service (KMS) to generate and manage customer master keys (CMKs) and encrypt data in Amazon S3.

AWS Key Management Service (KMS) provides a fully managed service for creating and controlling encryption keys, integrated with many AWS services like S3 for encryption at rest and in transit. It offers strict access control and auditing capabilities, which are crucial for confidential data.

Why the other options are wrong

  • B. Storing keys in application code is a major security risk and violates best practices for key management.
  • C. Self-managed keys on an EC2 instance increase operational overhead and security responsibility; KMS offers a more secure and managed approach.
  • D. While Secrets Manager can store secrets, KMS is specifically designed for cryptographic operations and key lifecycle management, providing a more robust solution for encryption keys, especially when integrated directly with services like S3.

AWS Key Management Service (KMS)

A managed service that makes it easy for you to create and control the encryption keys used to encrypt your data, providing centralized key management and strong security controls.

  • Integrates with many AWS services for encryption.
  • Provides auditable usage of encryption keys.
  • Offers customer master keys (CMKs) for strong control.

Memory trick: KMS keeps keys safe, S3 holds secrets, together they secure data.

More Development with AWS Services questions