AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A financial institution is building a new trading platform on AWS. They need to store highly sensitive customer trading data in Amazon S3. Due to strict regulatory compliance, all data at rest must be encrypted using encryption keys that are managed and controlled solely by the financial institution, and they must have an audit trail of all key usage. Which S3 encryption option should be chosen?

  1. AServer-Side Encryption with AWS KMS Managed Keys (SSE-KMS)
  2. BClient-Side Encryption with AWS KMS Customer Managed Keys (CMK)
  3. CServer-Side Encryption with S3-Managed Keys (SSE-S3)
  4. DServer-Side Encryption with Customer-Provided Keys (SSE-C)
Show answer & explanation

Correct answer: B. Client-Side Encryption with AWS KMS Customer Managed Keys (CMK)

Client-Side Encryption (CSE) with AWS KMS Customer Managed Keys (CMK) allows the financial institution to encrypt data on their side before sending it to S3, using keys they full control in KMS. This setup provides an audit trail of key usage through AWS CloudTrail, meeting the strict regulatory and key management requirements.

Why the other options are wrong

  • A. SSE-KMS uses KMS keys, but AWS manages the key material; while it provides an audit trail, the institution doesn't have sole control over the key material generation or storage outside of KMS.
  • C. SSE-S3 uses keys managed entirely by AWS, which does not meet the requirement for keys managed and controlled solely by the institution.
  • D. SSE-C allows the customer to provide the encryption key, but S3 performs the encryption/decryption, and it doesn't integrate directly with KMS for key management or provide a native audit trail of key usage within KMS.

S3 Encryption with Customer Control

Using S3 encryption options that provide the highest level of control over encryption keys and auditability for sensitive data.

  • SSE-S3: AWS manages keys fully.
  • SSE-KMS: AWS KMS manages keys, some customer control over policy.
  • SSE-C: Customer provides key, S3 encrypts.
  • Client-Side Encryption with CMK: Customer encrypts data with their KMS CMK before upload, full key control and auditability.

Memory trick: Client-Side KMS CMK: Control Your Own Key.

More Design Secure Architectures questions