AWS Certified Solutions Architect – Associate (SAA-C03)Design Cost-Optimized ArchitecturesHard

A startup is building a new application that will store highly sensitive customer data in an Amazon RDS PostgreSQL database. Regulatory compliance requires that all data at rest must be encrypted using customer-managed keys, and the encryption solution must be cost-effective. Which encryption approach should be used?

  1. AEncrypt the data within the application before storing it in RDS.
  2. BEnable encryption at rest using AWS-managed keys for RDS.
  3. CProvision an EC2 instance and manually encrypt the database using open-source tools.
  4. DUse AWS Key Management Service (KMS) Customer Managed Keys (CMKs) for RDS encryption.
Show answer & explanation

Correct answer: D. Use AWS Key Management Service (KMS) Customer Managed Keys (CMKs) for RDS encryption.

Regulatory compliance requiring customer-managed keys directly points to AWS KMS CMKs. Using KMS CMKs for RDS encryption provides the necessary control over the encryption keys while leveraging RDS's integrated encryption capabilities, which is a cost-effective and managed solution compared to manual encryption or self-managed keys on EC2.

Why the other options are wrong

  • A. Encrypting data within the application adds complexity, potential performance overhead, and management burden to the application developers.
  • B. AWS-managed keys do not meet the 'customer-managed keys' compliance requirement.
  • C. Manually encrypting on EC2 is high operational overhead, lacks the benefits of RDS, and is not cost-effective for a managed database solution.

AWS KMS Customer Managed Keys (CMKs)

Customer Managed Keys (CMKs) in AWS Key Management Service (KMS) are encryption keys that you create, own, and manage. You have full control over their lifecycle, including creation, rotation, and access policies, which is essential for meeting specific regulatory compliance requirements for data encryption.

  • Customer has full control over key lifecycle and access policies.
  • Integrates with many AWS services for encryption at rest.
  • Essential for compliance requirements needing customer control over encryption keys.

Memory trick: CMKs: Your keys, your rules, your compliance tools.

More Design Cost-Optimized Architectures questions