AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy

A financial services company is migrating its on-premises applications to AWS. They need to ensure that all data in transit between their Amazon EC2 instances and Amazon S3 buckets within the same AWS region is encrypted. Which of the following is the MOST cost-effective and secure way to meet this requirement?

  1. ADeploy a dedicated network appliance to encrypt traffic before it reaches S3.
  2. BImplement client-side encryption for all data uploaded to S3.
  3. CConfigure S3 bucket policies to enforce HTTPS/TLS for all data transfers.
  4. DUse a VPN connection between EC2 instances and S3 for encrypted traffic.
Show answer & explanation

Correct answer: C. Configure S3 bucket policies to enforce HTTPS/TLS for all data transfers.

Amazon S3 supports HTTPS/TLS for all data transfers, which encrypts data in transit. Enforcing this via a bucket policy is a straightforward, cost-effective, and secure method within the AWS environment.

Why the other options are wrong

  • A. Deploying a dedicated network appliance for encryption introduces unnecessary cost, operational overhead, and a potential bottleneck for a feature S3 provides natively.
  • B. Client-side encryption adds application overhead and complexity, and while it encrypts data in transit, it's not the most cost-effective or simplest solution for general in-transit encryption to S3.
  • D. Using a VPN within the same AWS region for S3 access is an overly complex and expensive solution; S3 natively supports TLS for secure communication over public endpoints.

S3 Data in Transit Encryption

Ensuring data is encrypted while it moves between an application and Amazon S3.

  • S3 supports HTTPS/TLS for all data transfers by default.
  • Bucket policies can enforce HTTPS/TLS to ensure secure connections.
  • This method encrypts data as it travels over the network.

Memory trick: Secure S3 with Simple TLS Tactics.

More Design Secure Architectures questions