AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium
A global media company uses Amazon S3 to store large volumes of video and image assets. They need to ensure that all objects uploaded to a specific S3 bucket are encrypted at rest using a key that they fully control and manage, including rotation policies. The solution must integrate seamlessly with existing AWS services and allow for auditing of key usage. Which S3 encryption option should they choose?
- AServer-Side Encryption with AWS Key Management Service (SSE-KMS)
- BClient-Side Encryption with a customer-managed encryption library
- CServer-Side Encryption with Customer-Provided Keys (SSE-C)
- DServer-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
Show answer & explanationAnswer & explanation
Correct answer: A. Server-Side Encryption with AWS Key Management Service (SSE-KMS)
SSE-KMS allows the customer to use AWS Key Management Service (KMS) for managing encryption keys. This provides full control over the key, including defining its rotation policy, and integrates with AWS CloudTrail for auditing key usage. This meets all specified requirements.
Why the other options are wrong
- B. Client-side encryption requires application-level changes and external key management, which might not integrate seamlessly with existing AWS services for auditing key usage as effectively as KMS.
- C. SSE-C requires the customer to provide the encryption key with each request, which can be complex to manage at scale and doesn't offer integrated key rotation or auditing through AWS services.
- D. SSE-S3 uses keys managed entirely by AWS, which does not give the customer full control over key management or rotation policies.
S3 SSE-KMS
Server-Side Encryption using AWS Key Management Service (KMS) managed keys, offering customer control over key policies and auditing.
- Uses AWS KMS to manage encryption keys.
- Customer retains full control over key policies, including rotation.
- Integrates with AWS CloudTrail for auditing key usage.
Memory trick: KMS keys give you the reins for S3 security.