AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A manufacturing company uses AWS IoT Core to collect data from factory sensors. This data is sensitive and must be securely stored and processed. They need to ensure that messages published to AWS IoT Core are encrypted end-to-end between the devices and the IoT Core service, and that only authorized devices can publish messages. Which two mechanisms are essential to achieve this?

  1. AUtilize X.509 certificates for device identity and mutual TLS for secure communication.
  2. BImplement mutual TLS authentication for devices and use AWS KMS for message encryption.
  3. CUse S3 bucket policies for device authentication and enable S3 default encryption for data at rest.
  4. DConfigure AWS WAF to filter incoming messages and use AWS Certificate Manager for device certificates.
Show answer & explanation

Correct answer: A. Utilize X.509 certificates for device identity and mutual TLS for secure communication.

X.509 certificates are used by AWS IoT Core for device authentication and authorization. Mutual TLS (mTLS) ensures secure, encrypted, and authenticated communication between the device and IoT Core, fulfilling both the end-to-end encryption and authorized device requirements.

Why the other options are wrong

  • B. While KMS can encrypt data, mutual TLS is the primary mechanism for secure communication and device authentication within IoT Core, and KMS is not directly used for message encryption in transit to IoT Core.
  • C. S3 bucket policies and S3 encryption are for data storage, not for device authentication or end-to-end encryption of messages in transit to IoT Core.
  • D. AWS WAF is for web applications, not for IoT device message filtering. AWS Certificate Manager can issue certificates but X.509 certificates are the standard for IoT device identity with IoT Core.

AWS IoT Core Security

AWS IoT Core secures device communication and data with mechanisms like X.509 certificates and mutual TLS.

  • X.509 certificates authenticate devices.
  • Mutual TLS encrypts data in transit and verifies both ends of the connection.
  • IoT Core policies authorize device actions.

Memory trick: IoT's X.509 and mTLS Seal the Deal.

More Design Secure Architectures questions