AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A startup is building a new application that processes sensitive user data and stores it in an Amazon DynamoDB table. Due to compliance requirements, all data in the DynamoDB table must be encrypted at rest using a customer-managed key (CMK) from AWS Key Management Service (KMS). Which DynamoDB encryption option should the Solutions Architect recommend?

  1. ADynamoDB encryption with customer managed key (CMK)
  2. BDynamoDB encryption with AWS owned key
  3. CDynamoDB encryption with AWS managed key
  4. DDynamoDB encryption with client-side encryption
Show answer & explanation

Correct answer: A. DynamoDB encryption with customer managed key (CMK)

DynamoDB encryption with a customer managed key (CMK) allows the customer to have full control over the encryption key used for their DynamoDB table, including key policies, rotation, and auditability, which satisfies the requirement for using a CMK from AWS KMS.

Why the other options are wrong

  • B. AWS owned keys are fully managed by AWS and do not provide customer control over key policies or auditability.
  • C. AWS managed keys are managed by AWS on behalf of the customer, offering less control than a CMK, which is explicitly requested.
  • D. Client-side encryption encrypts data before it reaches DynamoDB, but the question specifically asks for DynamoDB encryption using a CMK from KMS, implying server-side encryption with KMS.

DynamoDB Encryption with CMK

DynamoDB encryption with a customer managed key (CMK) from AWS Key Management Service (KMS) provides server-side encryption for DynamoDB tables where the customer has full control over the encryption key.

  • Uses a CMK managed in AWS KMS.
  • Customer controls key policies, rotation, and usage.
  • Provides an audit trail of key usage via CloudTrail.

Memory trick: Keys Control Data, Customer's Choice.

More Design Secure Architectures questions