AWS Certified Data Engineer – AssociateData Governance and SecurityHard
A data engineering team is building a real-time analytics pipeline using Amazon Kinesis Data Streams. The data contains sensitive customer information that must be encrypted in transit from the producers to the Kinesis stream. Additionally, the data must be encrypted at rest within the Kinesis stream. Which combination of encryption methods should be implemented?
- ASSL/TLS for in-transit encryption and Server-Side Encryption with KMS for at-rest encryption.
- BVPC endpoints for in-transit encryption and Kinesis Client-Side Encryption for at-rest encryption.
- CHTTPS for in-transit encryption and Kinesis Client-Side Encryption for at-rest encryption.
- DAWS PrivateLink for in-transit encryption and Server-Side Encryption with Kinesis managed keys for at-rest encryption.
Show answer & explanationAnswer & explanation
Correct answer: A. SSL/TLS for in-transit encryption and Server-Side Encryption with KMS for at-rest encryption.
All data sent to Kinesis Data Streams is encrypted in transit using SSL/TLS endpoints, which is a standard security measure. For encryption at rest within the stream, Kinesis Data Streams supports Server-Side Encryption (SSE) using AWS Key Management Service (KMS). This combination provides both in-transit and at-rest encryption as required.
Why the other options are wrong
- B. VPC endpoints provide private connectivity but do not inherently encrypt data in transit; SSL/TLS still handles that. Kinesis Client-Side Encryption is not the native at-rest encryption for Kinesis Streams.
- C. HTTPS is a form of SSL/TLS, but Kinesis Client-Side Encryption is not an AWS-native 'at rest' option for Kinesis Streams itself; rather, it's typically for data before it enters Kinesis or after it leaves.
- D. AWS PrivateLink provides private connectivity but doesn't handle encryption of data in transit itself. Kinesis Streams does not offer 'Kinesis managed keys' for SSE; it uses KMS-managed keys or customer-managed KMS keys.
Kinesis Data Streams Encryption
Amazon Kinesis Data Streams provides encryption for data both in transit (using SSL/TLS) and at rest (using Server-Side Encryption with AWS KMS).
- In-transit encryption is automatic via SSL/TLS endpoints
- At-rest encryption uses Server-Side Encryption (SSE) with AWS KMS
- Customers can choose AWS managed KMS keys or customer managed KMS keys for SSE
Memory trick: Kinesis is secure: SSL in transit, KMS at rest.