AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityHard

A global software company is developing a new serverless application on AWS that will process sensitive customer data. The application uses AWS Lambda functions, Amazon S3 for data storage, and Amazon DynamoDB for its database. The company has a strict security policy that mandates all data at rest must be encrypted with keys that are managed within a FIPS 140-2 Level 3 validated hardware security module. Additionally, key usage must be centrally auditable. Which AWS service should the Solutions Architect recommend for key management?

  1. AAWS Certificate Manager (ACM) for cryptographic key storage.
  2. BAWS Secrets Manager for storing encryption keys securely.
  3. CAmazon CloudHSM for managing encryption keys.
  4. DAWS Key Management Service (KMS) with customer-managed keys (CMKs).
Show answer & explanation

Correct answer: C. Amazon CloudHSM for managing encryption keys.

Amazon CloudHSM provides dedicated hardware security modules (HSMs) that are FIPS 140-2 Level 3 validated, meeting the stringent compliance requirement. It allows customers to control their encryption keys within a tamper-resistant environment and ensures that key usage is auditable. While KMS offers FIPS 140-2 Level 2, CloudHSM is required for Level 3.

Why the other options are wrong

  • A. AWS Certificate Manager (ACM) is for managing SSL/TLS certificates for network encryption, not for managing general encryption keys for data at rest within a FIPS-validated HSM.
  • B. AWS Secrets Manager is for managing application secrets like database credentials, not for managing encryption keys for data at rest with FIPS 140-2 Level 3 validation.
  • D. AWS KMS provides FIPS 140-2 Level 2 validated hardware for key storage. The requirement specifically states FIPS 140-2 Level 3, which KMS does not offer at the customer-managed key level. While KMS can use CloudHSM as a custom key store, CloudHSM itself is the more direct answer for the Level 3 requirement.

Amazon CloudHSM

A cloud-based hardware security module (HSM) service that enables you to easily generate and use your own encryption keys on the AWS Cloud.

  • Provides FIPS 140-2 Level 3 validated hardware for key storage.
  • Offers single-tenant HSMs for dedicated key isolation.
  • Gives customers exclusive control over their cryptographic keys.

Memory trick: CloudHSM: Hardware Security, Highest FIPS Level.

More Design Solutions for Organizational Complexity questions