AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy
A company is deploying a new web application on AWS that will store sensitive customer data. The application needs to ensure that data at rest is encrypted and that access to the underlying storage is restricted only to authorized application components. Which AWS service and configuration would best meet these requirements?
- AAmazon RDS with KMS encryption and security groups to restrict database access.
- BAmazon DynamoDB with default encryption and fine-grained access control using IAM policies.
- CAmazon S3 with SSE-S3 encryption and bucket policies to restrict access.
- DAmazon EC2 instances with encrypted EBS volumes and IAM roles for instance profiles.
Show answer & explanationAnswer & explanation
Correct answer: A. Amazon RDS with KMS encryption and security groups to restrict database access.
For sensitive customer data in a web application's database, Amazon RDS with KMS encryption provides strong data-at-rest encryption. Security groups effectively restrict network access to the database instances, ensuring only authorized application components can connect.
Why the other options are wrong
- B. DynamoDB is a NoSQL database, and while it offers encryption and fine-grained access, the question implies a general web application, where RDS (relational) is often a common choice, and security groups are a more direct way to restrict network access than just IAM policies for database endpoints.
- C. S3 is object storage, not typically used as the primary database for a web application, and while it offers encryption and policies, RDS is more appropriate for structured application data.
- D. EC2 with EBS provides compute and storage, but RDS is a better managed service for databases, handling patching, backups, and scaling automatically. IAM roles restrict EC2 instance permissions, not direct database access.
RDS Encryption & Access Control
Amazon RDS allows encryption of data at rest using AWS KMS and uses security groups to control network access to database instances.
- Encrypts data at rest using AWS KMS.
- Security Groups control network access.
- Managed relational database service.
Memory trick: RDS: Restrict Data Securely