AWS Certified Data Engineer – AssociateData Governance and SecurityMedium

A data analytics team is building a new application that will store sensitive customer data in an Amazon DynamoDB table. To meet compliance requirements, the data must be encrypted at rest. The security team insists on using customer-managed keys for encryption to maintain full control over the encryption key lifecycle. Which encryption option should the team choose for DynamoDB?

  1. AAWS owned key
  2. BClient-side encryption
  3. CAWS managed key (CMK)
  4. DCustomer managed key (CMK)
Show answer & explanation

Correct answer: D. Customer managed key (CMK)

DynamoDB encryption at rest with a Customer Managed Key (CMK) allows the customer to have full control over the encryption key lifecycle, including creating, rotating, enabling, and disabling the key. This directly addresses the security team's requirement.

Why the other options are wrong

  • A. AWS owned key is the default and AWS manages the key completely, which doesn't meet the requirement for customer control.
  • B. Client-side encryption would require the application to handle encryption/decryption, adding significant complexity and operational overhead, and is not a direct DynamoDB encryption at rest option.
  • C. AWS managed key (CMK) is managed by AWS KMS on the customer's behalf, but the customer has less control over its lifecycle compared to a customer managed key.

DynamoDB Encryption with CMK

DynamoDB encryption at rest with a Customer Managed Key (CMK) uses a key created and managed by the customer within AWS Key Management Service (KMS), providing full control over the key's lifecycle.

  • Customer has full control over the key lifecycle (create, rotate, enable, disable)
  • Key usage is logged in CloudTrail
  • Provides highest level of control for compliance

Memory trick: Customer Managed Key gives full control for DynamoDB.

More Data Governance and Security questions