AWS Certified Machine Learning – SpecialtyData EngineeringEasy
A data engineering team is designing a new machine learning pipeline that will process sensitive customer data. They need to ensure that the data remains encrypted both at rest and in transit, and that access is strictly controlled. Which combination of AWS services and features provides the most robust solution for securing this data within an Amazon S3 data lake?
- AStore data in encrypted Amazon EBS volumes attached to EC2 instances and use security groups for network access control.
- BEnable S3 default encryption with KMS keys for data at rest, use HTTPS for data in transit, and implement IAM policies for access control.
- CUse S3 bucket policies for access control and client-side encryption for data at rest and in transit.
- DEncrypt data using server-side encryption with S3-managed keys (SSE-S3) and rely on VPC endpoints for secure data transfer.
Show answer & explanationAnswer & explanation
Correct answer: B. Enable S3 default encryption with KMS keys for data at rest, use HTTPS for data in transit, and implement IAM policies for access control.
To ensure robust security for sensitive data in an S3 data lake, encryption at rest using KMS keys provides strong protection and auditability. HTTPS ensures data is encrypted in transit, and IAM policies offer granular access control, making this the most comprehensive solution.
Why the other options are wrong
- A. Storing data in EBS volumes moves it out of the S3 data lake paradigm and adds operational overhead; S3 is designed for scalable data lake storage.
- C. Client-side encryption can be complex to manage at scale, and S3 bucket policies alone might not cover all encryption requirements.
- D. SSE-S3 is simpler but offers less control than KMS. VPC endpoints secure network paths but don't inherently encrypt data at the application layer or manage access like IAM.
S3 Data Security Best Practices
A combination of encryption, access control, and secure communication protocols to protect data stored in Amazon S3 for machine learning workloads.
- Encryption at rest: Use Server-Side Encryption with KMS (SSE-KMS) for managed keys and auditability.
- Encryption in transit: Enforce HTTPS for all data transfer to and from S3.
- Access control: Implement granular permissions using IAM policies and S3 bucket policies.
Memory trick: Secure S3, Keep Data Safe, IAM and KMS are the Keys!