AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy
A company is building a new application that will store highly sensitive customer data in an Amazon DynamoDB table. Due to compliance requirements, all data must be encrypted at rest, and the encryption keys must be managed by the customer. The solution must also integrate seamlessly with AWS Key Management Service (KMS) for key lifecycle management. Which DynamoDB encryption option should be implemented?
- ADynamoDB encryption using customer managed keys (CMK)
- BDynamoDB encryption using AWS owned keys
- CDynamoDB encryption with client-side encryption
- DDynamoDB encryption using AWS managed keys
Show answer & explanationAnswer & explanation
Correct answer: A. DynamoDB encryption using customer managed keys (CMK)
DynamoDB encryption using customer managed keys (CMK) allows customers to choose their own CMK from AWS KMS for encrypting their tables. This provides full control over the encryption key and integrates with KMS for key lifecycle management, meeting all the specified requirements.
Why the other options are wrong
- B. AWS owned keys are fully managed by AWS and do not provide customer control over the encryption key.
- C. Client-side encryption encrypts data before sending it to DynamoDB, but the question asks for a DynamoDB encryption option that leverages KMS for key management, which CMK provides for at-rest encryption.
- D. AWS managed keys are managed by AWS on the customer's behalf and do not provide the same level of granular control as CMKs.
DynamoDB Encryption with CMK
DynamoDB encryption using customer managed keys (CMK) allows users to specify an AWS KMS CMK for encrypting their DynamoDB tables, providing granular control over the key.
- Uses customer-managed keys from AWS KMS.
- Provides full control over key policies and lifecycle.
- Offers enhanced compliance and security for sensitive data.
Memory trick: DynamoDB's Keys: Own, Managed, or Customer's Choice.