AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityEasy
A multinational financial services company is developing a new, highly sensitive application that will process customer financial data. This application must meet stringent compliance requirements, including data residency within specific AWS Regions and encryption of all data at rest and in transit. The company requires full control over the encryption keys and wants to ensure that key usage is auditable. Which AWS service should be used to manage the encryption keys?
- AAWS Certificate Manager (ACM) for provisioning SSL/TLS certificates.
- BAWS Secrets Manager for storing and rotating database credentials.
- CAWS Key Management Service (KMS) with customer-managed keys (CMKs).
- DAmazon CloudHSM for hardware-based key storage and cryptographic operations.
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Key Management Service (KMS) with customer-managed keys (CMKs).
AWS Key Management Service (KMS) with customer-managed keys (CMKs) allows customers to create, manage, and control their encryption keys. KMS integrates with many AWS services to encrypt data at rest and in transit, and all key usage is logged to AWS CloudTrail, meeting the auditing requirements. CMKs provide the necessary control over keys.
Why the other options are wrong
- A. AWS Certificate Manager (ACM) is used for provisioning, managing, and deploying SSL/TLS certificates for securing network communications, not for managing general encryption keys for data at rest.
- B. AWS Secrets Manager is used for storing and rotating database credentials, API keys, and other secrets, not for managing encryption keys for data at rest and in transit.
- D. Amazon CloudHSM provides hardware security modules (HSMs) for cryptographic operations and key storage. While it offers high security and compliance, it requires more operational overhead to manage than KMS and might be an overkill if KMS CMKs already meet the stringent requirements, especially regarding integration with other AWS services and auditability which KMS provides natively.
AWS Key Management Service (KMS)
A managed service that makes it easy for you to create and control the encryption keys used to encrypt your data. KMS is integrated with most other AWS services.
- Manages encryption keys used by AWS services and applications.
- Supports customer-managed keys (CMKs) for granular control.
- Provides audit logs via AWS CloudTrail for key usage.
Memory trick: KMS: Your central key master for AWS security.