AWS Certified Data Engineer – AssociateData Governance and SecurityMedium

A data engineering team is designing a new real-time analytics pipeline using Amazon Kinesis Data Streams. The data being ingested contains payment card information (PCI) and other personally identifiable information (PII). Due to PCI DSS compliance, all data in transit through the Kinesis stream must be encrypted. The company requires that the encryption keys be managed centrally by AWS KMS, with the ability to audit key usage and rotate keys annually. Which Kinesis Data Streams encryption option should the team choose?

  1. AEncryption at rest using S3 for Kinesis Firehose delivery
  2. BServer-Side Encryption (SSE) with AWS KMS keys
  3. CServer-Side Encryption (SSE) with Kinesis-managed keys
  4. DClient-Side Encryption before sending to Kinesis
Show answer & explanation

Correct answer: B. Server-Side Encryption (SSE) with AWS KMS keys

Kinesis Data Streams Server-Side Encryption (SSE) with AWS KMS keys encrypts data using a CMK from AWS KMS. This ensures data in transit is encrypted, allows central key management, provides auditability via CloudTrail, and supports key rotation, meeting all compliance requirements.

Why the other options are wrong

  • A. This option describes encryption for data delivered to S3 via Kinesis Firehose, not encryption for data within the Kinesis Data Stream itself during transit, which is the primary requirement.
  • C. SSE with Kinesis-managed keys (default encryption) uses AWS-managed keys, which do not offer the same level of customer control, auditability, or explicit key rotation as KMS keys.
  • D. Client-Side Encryption requires the client to manage encryption/decryption, which is not what 'managed centrally by AWS KMS' implies, and it adds client-side complexity.

Kinesis SSE with KMS

Kinesis Data Streams Server-Side Encryption (SSE) with AWS KMS keys encrypts data as it is written to the stream and decrypts it as it is read, using customer-managed keys (CMKs) from AWS KMS.

  • Encrypts data in transit within the Kinesis stream.
  • Uses CMKs from AWS KMS for encryption.
  • Enables auditing of key usage and supports key rotation.

Memory trick: KMS Keys Keep Kinesis Streams Secure.

More Data Governance and Security questions