AWS Certified Machine Learning – SpecialtyData EngineeringHard
A research institution is collecting highly sensitive genomic data from various sources. They need a secure and auditable method to ingest this data into an S3 data lake, ensuring that all data transfers are encrypted end-to-end and access is logged. The data sources are often on-premises and generate large files. Which AWS service and configuration combination provides the most secure and auditable data collection for this scenario?
- AAWS Transfer Family SFTP endpoint with S3 as destination, combined with S3 Access Logs.
- BDirect upload to S3 using the AWS CLI with client-side encryption.
- CAWS DataSync agent on-premises, transferring to S3 with KMS encryption and CloudTrail logging.
- DAmazon S3 presigned URLs for direct uploads, with S3 bucket policies for access control.
Show answer & explanationAnswer & explanation
Correct answer: C. AWS DataSync agent on-premises, transferring to S3 with KMS encryption and CloudTrail logging.
AWS DataSync is designed for secure, online data transfers between on-premises storage and S3 at scale. It encrypts data in-transit, and when combined with S3 default encryption using KMS and CloudTrail for logging, it provides a highly secure, auditable, and managed solution for sensitive data ingestion from on-premises sources.
Why the other options are wrong
- A. AWS Transfer Family SFTP provides a secure channel, but DataSync is more optimized for large-scale, automated transfers and integrates better with KMS for encryption at rest and CloudTrail for comprehensive auditing across the transfer process.
- B. Client-side encryption requires careful key management on the client side and doesn't inherently provide the managed transfer, auditability, and scalability of DataSync for large on-premises data.
- D. S3 presigned URLs offer temporary access but are primarily for individual uploads/downloads, not for managed, large-scale, auditable ingestion from on-premises sources, and managing client-side encryption and auditing would be manual.
Secure On-Premises to S3 Ingestion
Utilizing AWS services like DataSync, KMS, and CloudTrail to securely, scalably, and audibly transfer large volumes of sensitive data from on-premises environments to an S3 data lake.
- AWS DataSync: Optimized, secure data transfer from on-premises.
- AWS KMS: Manages encryption keys for data at rest in S3.
- AWS CloudTrail: Provides activity logs for auditing data access and transfers.
Memory trick: DataSync moves it, KMS encrypts it, CloudTrail records it!