AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium
A financial institution is migrating its on-premises data warehouse to AWS. The data warehouse contains highly sensitive customer financial records that must be encrypted at rest. The security team requires that the encryption keys be managed and rotated automatically by an AWS service, and that they have an audit trail of key usage. Which encryption option for Amazon S3 buckets best meets these requirements?
- AClient-Side Encryption
- BServer-Side Encryption with Customer-Provided Keys (SSE-C)
- CServer-Side Encryption with AWS Key Management Service (SSE-KMS)
- DServer-Side Encryption with S3-Managed Keys (SSE-S3)
Show answer & explanationAnswer & explanation
Correct answer: C. Server-Side Encryption with AWS Key Management Service (SSE-KMS)
SSE-KMS uses AWS KMS for key management, which provides automatic key rotation, an audit trail via AWS CloudTrail, and strong security controls. SSE-S3 manages keys but lacks the audit and control features. SSE-C and Client-Side Encryption require the customer to manage keys, which doesn't meet the requirement for AWS-managed key rotation and auditing.
Why the other options are wrong
- A. Client-Side Encryption requires the customer to encrypt data before uploading it to S3 and manage their own keys, failing to meet the requirement for AWS-managed key rotation and auditing.
- B. SSE-C requires the customer to provide and manage their own encryption keys, which does not meet the requirement for AWS-managed key rotation or an audit trail through AWS services.
- D. SSE-S3 uses AWS-managed keys but does not provide the same level of granular control, auditing capabilities, or automatic key rotation management as KMS.
S3 SSE-KMS
Server-Side Encryption with AWS Key Management Service (SSE-KMS) uses AWS KMS to manage encryption keys, offering enhanced security, auditing, and key rotation capabilities for data stored in S3.
- Uses AWS KMS customer master keys (CMKs) for encryption.
- Provides an audit trail of key usage via AWS CloudTrail.
- Supports automatic key rotation.
Memory trick: KMS Keys Keep Sensitive S3 Safe and Trackable.