AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium
A highly regulated organization is building a new application on AWS that processes protected health information (PHI). The data will be stored in an Amazon DynamoDB table. Due to strict compliance requirements, all data must be encrypted at rest using a dedicated encryption key that the organization has full control over, including its creation, rotation, and access policies. Which DynamoDB encryption option meets these requirements?
- ADynamoDB encryption with customer managed key (CMK)
- BDynamoDB encryption with AWS managed key
- CDynamoDB encryption with AWS owned key
- DDynamoDB encryption with client-side encryption
Show answer & explanationAnswer & explanation
Correct answer: A. DynamoDB encryption with customer managed key (CMK)
DynamoDB encryption with a customer managed key (CMK) allows the organization to create, manage, and control the lifecycle and access policies of their encryption keys through AWS KMS, meeting the requirement for full control over a dedicated key for PHI.
Why the other options are wrong
- B. AWS managed keys are managed by AWS on behalf of the customer, offering less granular control than a customer managed key (CMK), which is explicitly required for full control.
- C. AWS owned keys are fully managed by AWS and do not provide the customer with control over key creation, rotation, or access policies.
- D. Client-side encryption encrypts data before it reaches DynamoDB; while it offers key control, the question implies server-side encryption with a dedicated key managed within AWS, making CMK the more direct and integrated solution for DynamoDB.
DynamoDB Encryption with CMK
DynamoDB encryption with a customer managed key (CMK) from AWS Key Management Service (KMS) provides server-side encryption with full customer control over the encryption key's lifecycle, policies, and auditing.
- Uses a CMK from AWS KMS.
- Customer has full control over key creation, rotation, and access policies.
- Integrates with CloudTrail for auditing key usage.
- Essential for strict compliance requirements needing key control.
Memory trick: CMK: Complete Management for Keys.