AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard
A financial institution requires that all data stored in Amazon S3 must be encrypted at rest using a key that they provide and manage themselves outside of AWS. They need to ensure that Amazon S3 only accepts objects that are encrypted with these specific customer-provided keys. The solution must also minimize operational overhead for key management within AWS. Which S3 encryption option should they choose?
- AServer-Side Encryption with Customer-Provided Keys (SSE-C)
- BServer-Side Encryption with AWS Key Management Service (SSE-KMS)
- CServer-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
- DClient-Side Encryption with a customer-managed encryption library and external HSM
Show answer & explanationAnswer & explanation
Correct answer: A. Server-Side Encryption with Customer-Provided Keys (SSE-C)
SSE-C allows the customer to provide their own encryption keys as part of the S3 API requests. S3 performs the encryption/decryption using this key. A bucket policy can be used to enforce that all objects uploaded to the bucket must be encrypted with SSE-C, ensuring the customer's provided key is always used. This meets the requirement for a customer-provided and managed key outside of AWS with minimal AWS-side key management overhead.
Why the other options are wrong
- B. SSE-KMS uses keys managed within AWS KMS, not keys provided and managed by the customer outside of AWS.
- C. SSE-S3 uses keys entirely managed by AWS, not customer-provided or managed outside AWS.
- D. Client-Side Encryption requires the client application to encrypt data before sending it to S3, which shifts the encryption burden entirely to the application and doesn't leverage S3's server-side encryption capabilities to enforce the key usage at the bucket level.
S3 SSE-C
Server-Side Encryption with Customer-Provided Keys (SSE-C) allows customers to manage their own encryption keys and provide them to Amazon S3 as part of API requests.
- Customer provides and manages the encryption key.
- Key is passed with each S3 API request (PUT, GET).
- S3 performs the encryption/decryption using the provided key.
- Allows enforcement via bucket policies to require SSE-C for uploads.
Memory trick: SSE-C: 'S'3 'S'ecurity 'E'xternally 'C'ontrolled.