AWS Certified Solutions Architect – Associate (SAA-C03)Design Cost-Optimized ArchitecturesHard

A company is designing a new application that will store highly sensitive customer data. They need to ensure that the data is encrypted at rest and in transit, and that access is strictly controlled. Compliance requirements dictate that encryption keys must be managed and rotated automatically. Which AWS service should be used to manage the encryption keys in a cost-optimized and secure manner?

  1. AServer-side encryption with Amazon S3-managed keys (SSE-S3)
  2. BClient-side encryption using a custom key management system
  3. CAWS Key Management Service (KMS) with customer managed keys (CMKs)
  4. DAWS Secrets Manager for storing encryption keys
Show answer & explanation

Correct answer: C. AWS Key Management Service (KMS) with customer managed keys (CMKs)

AWS Key Management Service (KMS) provides a fully managed service for creating and controlling encryption keys. Using Customer Managed Keys (CMKs) in KMS allows the company to have full control over the keys, including automatic rotation, while AWS handles the underlying infrastructure and security, meeting compliance requirements for key management and rotation in a cost-optimized way compared to building a custom system.

Why the other options are wrong

  • A. SSE-S3 uses AWS-managed keys, which means the customer has no control over key rotation or management, failing to meet the requirement for the company to manage rotation.
  • B. A custom key management system is complex, expensive to build and maintain, and generally not cost-optimized compared to a managed service like KMS.
  • D. AWS Secrets Manager is for managing secrets like database credentials or API keys, not for managing encryption keys used for data encryption, though it can store KMS key ARNs, it doesn't provide the key management functionality itself.

AWS Key Management Service (KMS) CMKs

AWS Key Management Service (KMS) is a managed service that makes it easy for you to create and control the encryption keys used to encrypt your data. Customer Managed Keys (CMKs) give you full control over key policies and rotation.

  • Creates and manages cryptographic keys.
  • Integrates with most other AWS services.
  • Supports automatic key rotation for CMKs.
  • Highly available and secure hardware security modules (HSMs).

Memory trick: KMS is the master locksmith of your cloud, keeping your keys safe and turning them regularly.

More Design Cost-Optimized Architectures questions