AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A financial institution requires that all data stored in Amazon S3 must be encrypted at rest with encryption keys managed and controlled by the institution itself, not by AWS. Which S3 encryption option should be chosen?

  1. AServer-Side Encryption with Customer-provided keys (SSE-C)
  2. BServer-Side Encryption with S3-managed keys (SSE-S3)
  3. CClient-Side Encryption
  4. DServer-Side Encryption with KMS-managed keys (SSE-KMS)
Show answer & explanation

Correct answer: A. Server-Side Encryption with Customer-provided keys (SSE-C)

SSE-C allows customers to manage their own encryption keys and provide them to S3 with each object operation. S3 performs the encryption/decryption using the provided key, but AWS does not store or manage the key, meeting the requirement for customer control.

Why the other options are wrong

  • B. SSE-S3 uses keys managed by AWS, not the customer.
  • C. Client-Side Encryption involves encrypting data before sending it to S3. While it means the customer controls the key, SSE-C is a server-side option that explicitly addresses the requirement of the customer providing the key to S3 for encryption/decryption.
  • D. SSE-KMS uses keys managed within AWS KMS, which while offering more control than SSE-S3, the keys are still managed by KMS, not directly by the customer outside of AWS.

S3 SSE-C

Server-Side Encryption with Customer-provided Keys (SSE-C) allows customers to provide their own encryption keys for S3 to use for data at rest encryption.

  • Customer provides and manages the encryption key.
  • S3 performs encryption/decryption using the provided key.
  • Key is not stored by AWS.

Memory trick: KMS, S3, C: Keys Securely Managed

More Design Secure Architectures questions