AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is building an application that uses Amazon SQS for message queuing. The messages contain sensitive customer information. The security team requires that all messages at rest within the SQS queues must be encrypted. The solution should also allow for auditability of key usage. Which SQS encryption option should the developer choose to meet these requirements?

  1. AUse an encrypted Amazon S3 bucket to store messages and put S3 object keys in SQS.
  2. BServer-Side Encryption (SSE) with AWS Key Management Service (KMS) keys (SSE-KMS).
  3. CServer-Side Encryption (SSE) with SQS managed keys (SSE-SQS).
  4. DClient-side encryption before sending messages to SQS.
Show answer & explanation

Correct answer: B. Server-Side Encryption (SSE) with AWS Key Management Service (KMS) keys (SSE-KMS).

SSE with KMS keys (SSE-KMS) for SQS provides encryption at rest for messages and integrates with AWS KMS. This allows for auditability of key usage through AWS CloudTrail logs, which track KMS API calls, directly meeting the auditability requirement.

Why the other options are wrong

  • A. This is a workaround that adds complexity and cost, and doesn't directly encrypt SQS messages themselves.
  • C. SSE-SQS encrypts messages with SQS-managed keys, but does not provide the same level of auditability (via CloudTrail for KMS actions) as SSE-KMS.
  • D. Client-side encryption adds complexity and doesn't leverage SQS native encryption at rest with auditability.

SQS Server-Side Encryption (SSE-KMS)

SQS SSE-KMS encrypts messages at rest in SQS queues using AWS Key Management Service (KMS). It leverages KMS customer master keys (CMKs), allowing for centralized key management and auditability of key usage via CloudTrail.

  • Encrypts messages at rest in SQS queues.
  • Uses AWS KMS keys (CMKs, AWS managed keys).
  • Provides auditability of key usage through CloudTrail logs for KMS actions.
  • Transparent to producers and consumers once configured.

Memory trick: SQS messages, encrypted with KMS, leave an audit trail.

More Security questions