AWS Certified Data Engineer – AssociateData Operations and MonitoringHard

A financial services company processes sensitive customer transaction data using an AWS Glue ETL pipeline. The pipeline runs hourly and moves data from encrypted S3 buckets to an encrypted Amazon Redshift cluster. Due to compliance requirements, the company must ensure that all data at rest and in transit within the Glue environment (e.g., temporary files, logs, scripts) is encrypted using customer-managed keys (CMKs) from AWS Key Management Service (KMS). Which set of configurations must be applied to meet this strict security requirement?

  1. AApply a bucket policy on S3 to enforce KMS encryption, and enable Glue security configurations with KMS CMKs for temporary storage, logs, and bookmarks.
  2. BEnsure all S3 buckets used by Glue are encrypted with KMS CMKs, and configure Glue connection to Redshift with SSL.
  3. CConfigure S3 bucket encryption with KMS CMKs, and enable Redshift KMS encryption.
  4. DEnable AWS Glue encryption settings for S3 data, CloudWatch Logs, and Job bookmarks using KMS CMKs.
Show answer & explanation

Correct answer: A. Apply a bucket policy on S3 to enforce KMS encryption, and enable Glue security configurations with KMS CMKs for temporary storage, logs, and bookmarks.

This option provides the most comprehensive and correct solution. While S3 bucket encryption is necessary, Glue's own security configurations specifically handle temporary storage, CloudWatch Logs, and Job bookmarks encryption (data at rest within Glue's operational environment) using KMS CMKs, which is critical for compliance. Enforcing S3 encryption via bucket policy ensures that incoming data into S3 also uses CMKs.

Why the other options are wrong

  • B. SSL for Redshift connection covers data in transit to Redshift, but the core requirement is about data at rest within the Glue environment (temp files, logs, scripts) and in S3 using CMKs. A Glue connection setting doesn't enforce S3 bucket encryption.
  • C. This covers the source and target data stores but not the intermediate data, logs, or temporary files generated by Glue itself, which is a key part of the requirement.
  • D. This addresses Glue's internal encryption settings but doesn't explicitly guarantee that the source/target S3 buckets are also using KMS CMKs, nor does it enforce it via policy for new data.

AWS Glue Security Configurations

A feature in AWS Glue that allows defining encryption settings for data at rest (S3 data stores, temporary S3 paths, CloudWatch Logs) and data in transit (SSL for connections) using AWS KMS keys.

  • Encrypts data written to S3 by Glue jobs.
  • Encrypts CloudWatch Logs generated by Glue jobs.
  • Encrypts Job bookmarks stored in S3.
  • Supports customer-managed KMS keys (CMKs).

Memory trick: Glue's Got KMS Keys for Every Spot: S3, Logs, and Temp Lots.

More Data Operations and Monitoring questions