AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium
A highly regulated organization is deploying a new application that processes protected health information (PHI). The application uses Amazon SQS for message queuing. The security team mandates that all messages in SQS queues must be encrypted at rest and in transit. Which solution ensures both requirements are met?
- AUse Amazon SNS to publish messages to an SQS queue with SSE enabled, and ensure SNS uses HTTPS.
- BConfigure client-side encryption for messages before sending them to SQS and enable SSE.
- CEnable Server-Side Encryption (SSE) for the SQS queue and ensure clients use HTTPS for communication.
- DCreate a private SQS queue within a VPC endpoint and enable SSE for the queue.
Show answer & explanationAnswer & explanation
Correct answer: C. Enable Server-Side Encryption (SSE) for the SQS queue and ensure clients use HTTPS for communication.
Enabling Server-Side Encryption (SSE) for an SQS queue ensures messages are encrypted at rest. For in-transit encryption, all communication with SQS should use HTTPS, which is the standard secure protocol for AWS API calls. This combination satisfies both requirements directly.
Why the other options are wrong
- A. SNS publishing to SQS can be used, but the core requirement is SQS encryption. While SNS uses HTTPS, it doesn't guarantee SQS messages are encrypted in transit between other clients and SQS, or encrypted at rest within SQS without explicit SSE.
- B. Client-side encryption handles encryption at rest (from the client's perspective) but adds complexity and doesn't replace the need for SSE for comprehensive at-rest encryption within SQS. HTTPS is still needed for in-transit encryption.
- D. Using a VPC endpoint provides private connectivity, but it doesn't inherently encrypt data in transit (HTTPS does that) nor does it provide at-rest encryption for the SQS queue itself without enabling SSE.
SQS Encryption
Amazon SQS supports Server-Side Encryption (SSE) for data at rest and relies on HTTPS for encryption of data in transit.
- SSE for SQS encrypts messages at rest using KMS.
- HTTPS ensures data is encrypted in transit.
- SQS is a fully managed message queuing service.
Memory trick: SQS: Secure Queues System