AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A healthcare startup is building a new application on AWS that handles Protected Health Information (PHI). The application uses Amazon DynamoDB to store patient data. Due to compliance requirements, all data at rest in DynamoDB must be encrypted. The security team also requires that the encryption keys are managed by a service that allows for easy integration with other AWS services and provides audit trails for key usage. Which encryption option should the startup choose for DynamoDB?

  1. ADynamoDB encryption with client-side encryption using an external key management system.
  2. BDynamoDB encryption with AWS owned keys.
  3. CDynamoDB encryption with AWS managed keys (default).
  4. DDynamoDB encryption with customer managed keys (CMK) in AWS KMS.
Show answer & explanation

Correct answer: D. DynamoDB encryption with customer managed keys (CMK) in AWS KMS.

DynamoDB encryption with customer managed keys (CMK) in AWS KMS allows the customer to create and manage their own encryption keys within AWS KMS. This provides full control over key policies, rotation, and enables audit trails through CloudTrail, meeting the compliance and security requirements for PHI.

Why the other options are wrong

  • A. Client-side encryption with an external system would require significant application changes and might not integrate seamlessly with AWS for auditing key usage as required.
  • B. AWS owned keys are fully managed by AWS and do not provide customer control over key policies or audit trails specific to the customer's keys.
  • C. AWS managed keys are also fully managed by AWS (default behavior), offering less control and specific auditability compared to CMKs.

DynamoDB Encryption with CMK

Encrypts DynamoDB data at rest using customer managed keys (CMK) stored in AWS Key Management Service (KMS).

  • Customer has full control over key policies and rotation.
  • Leverages AWS KMS for secure key storage and management.
  • Key usage can be audited via AWS CloudTrail.

Memory trick: CMKs give you the master key to DynamoDB's secrets.

More Design Secure Architectures questions