AWS Certified Data Engineer – AssociateData Governance and SecurityMedium
A financial institution is building a new real-time analytics pipeline using Amazon Kinesis Data Streams. Due to strict regulatory compliance, all data ingested into Kinesis must be encrypted at rest and in transit. The solution must also ensure that the encryption keys are managed by the financial institution and rotated automatically. Which Kinesis Data Streams encryption configuration meets these requirements?
- AServer-side encryption with Kinesis-managed keys
- BServer-side encryption with AWS KMS customer master keys (CMKs)
- CClient-side encryption using a custom encryption library
- DEncryption in transit using HTTPS endpoints only
Show answer & explanationAnswer & explanation
Correct answer: B. Server-side encryption with AWS KMS customer master keys (CMKs)
Server-side encryption with AWS KMS customer master keys (CMKs) for Kinesis Data Streams ensures data is encrypted at rest, allows the customer to manage and control key rotation, and provides an audit trail of key usage, fulfilling all stated requirements.
Why the other options are wrong
- A. Kinesis-managed keys are rotated by AWS and do not provide customer control over key management or rotation schedule.
- C. Client-side encryption requires custom implementation and management, adding complexity, and does not provide Kinesis-managed encryption at rest.
- D. HTTPS endpoints only provide encryption in transit, not encryption at rest for the data stored within the Kinesis stream.
Kinesis SSE with CMK
Server-Side Encryption (SSE) for Amazon Kinesis Data Streams using AWS KMS Customer Master Keys (CMKs) encrypts data at rest within the stream, allowing customers to control and audit their encryption keys.
- Encrypts data at rest in Kinesis streams.
- Keys managed by AWS KMS, controlled by customer.
- Supports automatic key rotation.
- Ensures compliance with strict security requirements.
Memory trick: KMS Keys Kinesis Securely