AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A highly regulated organization is building a new application on AWS that processes protected health information (PHI). The data will be stored in an Amazon DynamoDB table. Due to strict compliance requirements, all data must be encrypted at rest using a customer-managed key (CMK) from AWS KMS, and the organization needs to have full control over the key's lifecycle, including rotation and access policies. Which DynamoDB encryption option should be chosen?

  1. ADynamoDB client-side encryption
  2. BDynamoDB encryption using AWS owned keys
  3. CDynamoDB encryption using AWS managed keys
  4. DDynamoDB encryption using customer managed keys (CMK)
Show answer & explanation

Correct answer: D. DynamoDB encryption using customer managed keys (CMK)

DynamoDB encryption using customer managed keys (CMK) allows the organization to specify their own CMK from AWS KMS. This option provides the highest level of control over the encryption key, including its lifecycle, rotation, and access policies, which is critical for meeting strict compliance requirements for PHI and customer-managed keys.

Why the other options are wrong

  • A. Client-side encryption encrypts data before it reaches DynamoDB. While it uses customer keys, the question specifically asks for a DynamoDB encryption option that uses a CMK from AWS KMS for at-rest encryption, which CMK provides within the DynamoDB service.
  • B. AWS owned keys are fully managed by AWS and offer no customer control over the key lifecycle or policies, failing to meet the 'customer-managed key' requirement.
  • C. AWS managed keys are managed by AWS on behalf of the customer, offering less granular control over key policies and lifecycle compared to CMKs, thus not meeting the 'full control' requirement.

DynamoDB Encryption with CMK

DynamoDB encryption using customer managed keys (CMK) allows users to specify an AWS KMS CMK for encrypting their DynamoDB tables, providing granular control over the key's lifecycle and access policies.

  • Uses customer-managed keys from AWS KMS.
  • Provides full control over key policies, rotation, and lifecycle.
  • Essential for strict compliance requirements needing explicit key control.

Memory trick: PHI Protection: Customer's Keys, Complete Control.

More Design Secure Architectures questions