AWS Certified Data Engineer – AssociateData Governance and SecurityEasy
A data engineering team is designing a new data lake on AWS S3. The team needs to ensure that all data at rest is encrypted, but they also want to minimize operational overhead and avoid managing encryption keys. Which S3 encryption option should they choose?
- AServer-Side Encryption with Customer-provided keys (SSE-C)
- BServer-Side Encryption with KMS managed keys (SSE-KMS)
- CServer-Side Encryption with S3 managed keys (SSE-S3)
- DClient-Side Encryption with KMS managed keys
Show answer & explanationAnswer & explanation
Correct answer: C. Server-Side Encryption with S3 managed keys (SSE-S3)
SSE-S3 provides encryption at rest with minimal operational overhead as AWS handles key management entirely. This aligns with the requirement to avoid managing encryption keys.
Why the other options are wrong
- A. SSE-C requires the customer to provide and manage encryption keys, which is explicitly what the team wants to avoid.
- B. SSE-KMS uses AWS KMS for key management, which still involves some operational overhead compared to SSE-S3, as permissions to KMS keys need to be managed.
- D. Client-Side Encryption requires the client to encrypt and decrypt data, increasing operational overhead.
SSE-S3
Server-Side Encryption with S3 managed keys (SSE-S3) encrypts S3 objects using keys managed by AWS. It is the easiest way to encrypt data at rest in S3.
- AWS manages the encryption keys
- Objects are encrypted before saving to disk and decrypted when retrieved
- No additional cost for key management beyond S3 storage
Memory trick: Simple S3 Encryption means AWS handles Keys.