AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy
A healthcare startup is building a new application on AWS that handles Protected Health Information (PHI). They need to ensure that all sensitive data stored in Amazon DynamoDB is encrypted at rest to comply with HIPAA regulations. Which encryption option should they choose to meet this requirement with minimal operational overhead?
- AServer-side encryption with AWS Key Management Service (KMS) AWS managed keys.
- BServer-side encryption with AWS owned keys (default encryption).
- CServer-side encryption with AWS Key Management Service (KMS) customer managed keys (CMK).
- DClient-side encryption using a custom encryption library before sending data to DynamoDB.
Show answer & explanationAnswer & explanation
Correct answer: B. Server-side encryption with AWS owned keys (default encryption).
DynamoDB supports encryption at rest by default using AWS owned keys, which requires no additional configuration or management effort from the user, making it the option with minimal operational overhead while meeting the encryption requirement.
Why the other options are wrong
- A. Using KMS AWS managed keys provides encryption with less control than CMKs but still requires explicit selection and management compared to the default AWS owned keys.
- C. Using KMS CMKs offers more control over keys but introduces operational overhead for key creation, rotation, and access policy management.
- D. Client-side encryption adds significant operational overhead for key management, encryption/decryption logic, and application changes.
DynamoDB Encryption at Rest
DynamoDB tables are encrypted at rest by default, protecting data stored on disk.
- DynamoDB tables are encrypted by default using AWS owned keys.
- Users can choose AWS owned keys, AWS managed keys, or customer managed keys (CMKs).
- AWS owned keys offer the lowest operational overhead.
Memory trick: DynamoDB's Default Key Does the Job.