AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityMedium

A software company is developing a new serverless application that processes sensitive customer data. The application needs to comply with strict regulatory requirements for data encryption, access control, and auditing. The solutions architect must design a solution that ensures all data is encrypted at rest and in transit, access is restricted to authorized services and personnel, and all actions are logged for auditing purposes. The solution should also follow the principle of least privilege. Which combination of AWS services should be used?

  1. AStore data in Amazon DynamoDB with encryption at rest using AWS KMS, enforce access control with AWS IAM policies and resource-based policies, and enable AWS CloudTrail for auditing.
  2. BUtilize Amazon RDS for data storage with default encryption, implement Security Groups for network access control, and configure AWS Config for compliance checking.
  3. CUse Amazon S3 for data storage with server-side encryption (SSE-S3), AWS WAF for access control, and AWS Shield Advanced for auditing.
  4. DDeploy the application on AWS Lambda with environment variables for sensitive data, use Amazon Cognito for user authentication, and rely on Amazon CloudWatch Logs for auditing.
Show answer & explanation

Correct answer: A. Store data in Amazon DynamoDB with encryption at rest using AWS KMS, enforce access control with AWS IAM policies and resource-based policies, and enable AWS CloudTrail for auditing.

DynamoDB with AWS KMS for encryption at rest ensures data security. AWS IAM policies, especially resource-based policies, provide granular access control adhering to least privilege. AWS CloudTrail logs all API calls and actions, providing a comprehensive audit trail for compliance.

Why the other options are wrong

  • B. RDS default encryption is good, and Security Groups control network access. However, AWS Config is for configuration compliance, not for auditing all data access actions. IAM is needed for granular access control to the data itself.
  • C. SSE-S3 is good for S3, but WAF is for web application firewalling, not general access control for backend services, and Shield Advanced is for DDoS protection, not auditing.
  • D. Environment variables are not secure for sensitive data. Cognito is for user authentication, not for internal service access control. CloudWatch Logs are for application logs, but CloudTrail is specifically for auditing API actions on AWS resources.

AWS KMS

A managed service that makes it easy for you to create and control the encryption keys used to encrypt your data.

  • Integrates with many AWS services for encryption.
  • Provides centralized key management.
  • Supports customer managed keys (CMKs) and AWS managed keys.

Memory trick: KMS encrypts, IAM controls, CloudTrail audits.

More Design Solutions for Organizational Complexity questions