AWS Certified Machine Learning – SpecialtyData EngineeringHard

A research institution is collecting highly sensitive genomic data from various sources. They need a secure and auditable method to ingest this data into an S3 data lake, ensuring that all data transfers are encrypted end-to-end and access is logged. The data sources are often on-premises and generate large files. Which AWS service and configuration combination provides the most secure and auditable data collection for this scenario?

  1. AAWS Transfer Family SFTP endpoint with S3 as destination, combined with S3 Access Logs.
  2. BDirect upload to S3 using the AWS CLI with client-side encryption.
  3. CAWS DataSync agent on-premises, transferring to S3 with KMS encryption and CloudTrail logging.
  4. DAmazon S3 presigned URLs for direct uploads, with S3 bucket policies for access control.
Show answer & explanation

Correct answer: C. AWS DataSync agent on-premises, transferring to S3 with KMS encryption and CloudTrail logging.

AWS DataSync is designed for secure, online data transfers between on-premises storage and S3 at scale. It encrypts data in-transit, and when combined with S3 default encryption using KMS and CloudTrail for logging, it provides a highly secure, auditable, and managed solution for sensitive data ingestion from on-premises sources.

Why the other options are wrong

  • A. AWS Transfer Family SFTP provides a secure channel, but DataSync is more optimized for large-scale, automated transfers and integrates better with KMS for encryption at rest and CloudTrail for comprehensive auditing across the transfer process.
  • B. Client-side encryption requires careful key management on the client side and doesn't inherently provide the managed transfer, auditability, and scalability of DataSync for large on-premises data.
  • D. S3 presigned URLs offer temporary access but are primarily for individual uploads/downloads, not for managed, large-scale, auditable ingestion from on-premises sources, and managing client-side encryption and auditing would be manual.

Secure On-Premises to S3 Ingestion

Utilizing AWS services like DataSync, KMS, and CloudTrail to securely, scalably, and audibly transfer large volumes of sensitive data from on-premises environments to an S3 data lake.

  • AWS DataSync: Optimized, secure data transfer from on-premises.
  • AWS KMS: Manages encryption keys for data at rest in S3.
  • AWS CloudTrail: Provides activity logs for auditing data access and transfers.

Memory trick: DataSync moves it, KMS encrypts it, CloudTrail records it!

More Data Engineering questions