AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy
A company is deploying a new web application on AWS that requires sensitive user data to be stored in an Amazon S3 bucket. The company's security policy mandates that all data stored in S3 must be encrypted at rest using a customer-managed encryption key (CMK) that they control. Additionally, they need to ensure that access to this key is strictly controlled and audited. Which S3 encryption option should they choose to meet these requirements?
- AServer-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
- BClient-Side Encryption
- CServer-Side Encryption with Customer-Provided Keys (SSE-C)
- DServer-Side Encryption with AWS Key Management Service (SSE-KMS)
Show answer & explanationAnswer & explanation
Correct answer: D. Server-Side Encryption with AWS Key Management Service (SSE-KMS)
SSE-KMS allows customers to encrypt S3 objects using CMKs managed within AWS KMS, providing full control over the encryption key and enabling auditing of key usage. This directly meets the requirement for a customer-managed key with strict access control and auditing.
Why the other options are wrong
- A. SSE-S3 uses keys managed by AWS, not customer-managed, so it does not meet the requirement for a customer-controlled key.
- B. Client-side encryption encrypts data before it leaves the client, but the question specifically asks for an S3 encryption option that uses a customer-managed key with auditing capabilities, which SSE-KMS provides.
- C. SSE-C requires the customer to provide and manage their own encryption keys, which are sent with each S3 request; it does not leverage AWS KMS for key management or auditing.
SSE-KMS
Server-Side Encryption with AWS Key Management Service (SSE-KMS) allows S3 objects to be encrypted using customer master keys (CMKs) stored and managed in AWS KMS.
- Uses AWS KMS to manage encryption keys.
- Provides an audit trail of key usage through AWS CloudTrail.
- Offers more control over key rotation and permissions than SSE-S3.
Memory trick: KMS Keeps Keys Securely Managed for S3.