AWS Certified Machine Learning – SpecialtyData EngineeringEasy

A data engineering team is building a new machine learning pipeline that processes sensitive customer data. They need to ensure that the data is encrypted both in transit and at rest within Amazon S3 to meet compliance requirements. Additionally, they want to manage their own encryption keys to maintain full control over the data. Which encryption method should the team choose for their Amazon S3 buckets?

  1. AServer-Side Encryption with AWS Key Management Service (AWS KMS) managed keys (SSE-KMS)
  2. BServer-Side Encryption with Amazon S3-managed keys (SSE-S3)
  3. CServer-Side Encryption with customer-provided keys (SSE-C)
  4. DClient-Side Encryption with AWS KMS managed keys
Show answer & explanation

Correct answer: A. Server-Side Encryption with AWS Key Management Service (AWS KMS) managed keys (SSE-KMS)

SSE-KMS allows AWS to manage the encryption and decryption processes while giving the customer control over the encryption keys through AWS KMS, meeting both in-transit and at-rest encryption requirements with key management.

Why the other options are wrong

  • B. SSE-S3 uses keys managed by Amazon S3, which does not provide the customer with control over the keys.
  • C. SSE-C requires the customer to provide their own encryption keys with every request, which can be operationally complex and doesn't fully leverage AWS KMS for key management.
  • D. Client-Side Encryption is performed before data is sent to S3, but the question specifically asks for a method that ensures encryption within S3 and allows for customer management of keys through KMS, making SSE-KMS a more direct fit for server-side managed encryption with KMS keys.

SSE-KMS

Server-Side Encryption with AWS Key Management Service (AWS KMS) managed keys encrypts objects in Amazon S3 using KMS keys. It offers an audit trail of key usage and allows customers to define key access policies.

  • Encrypts data at rest in S3.
  • Keys are managed within AWS KMS, providing customer control and auditing.
  • AWS manages the encryption and decryption process.

Memory trick: KMS Keeps My Secrets Securely Stored.

More Data Engineering questions