AWS Certified Data Engineer – AssociateData Operations and MonitoringEasy
A data engineering team manages a critical ETL pipeline that processes sensitive customer data daily. The pipeline uses AWS Glue jobs, Amazon S3 for data storage, and AWS Lambda for orchestration. Recently, an audit revealed that while data at rest in S3 is encrypted, there is no explicit mechanism to ensure data in transit between Glue and S3, or Lambda and S3, is also encrypted. The team needs to implement a solution that encrypts all data in transit for this pipeline with minimal operational overhead, adhering to compliance requirements. Which AWS service or feature should they implement?
- AImplement client-side encryption within the Glue jobs and Lambda functions before sending data to S3.
- BConfigure S3 bucket policies to enforce server-side encryption for all uploads.
- CEnable SSL/TLS by default for all AWS service endpoints used by the pipeline.
- DUse AWS PrivateLink to establish private connectivity between Glue, Lambda, and S3.
Show answer & explanationAnswer & explanation
Correct answer: C. Enable SSL/TLS by default for all AWS service endpoints used by the pipeline.
AWS services, including Glue, Lambda, and S3, encrypt data in transit by default using SSL/TLS when communicating over public endpoints. There is no additional configuration needed for this standard security measure.
Why the other options are wrong
- A. Client-side encryption is an option but adds significant operational overhead and complexity compared to the default SSL/TLS encryption.
- B. S3 bucket policies enforce encryption at rest, not specifically data in transit between services.
- D. AWS PrivateLink provides private connectivity within the AWS network but does not inherently encrypt data in transit; SSL/TLS handles that.
AWS Data-in-Transit Encryption
AWS services automatically encrypt data in transit using SSL/TLS when communicating over public endpoints, ensuring secure communication between services by default.
- SSL/TLS is the default encryption protocol.
- Applies to communication over public endpoints.
- Requires no explicit configuration for default behavior.
Memory trick: Default AWS encryption is like a secure tunnel for your data.