AWS Certified Data Engineer – AssociateData Governance and SecurityMedium

A financial institution is migrating its on-premises data warehouse to Amazon Redshift. Regulatory requirements state that all data at rest within the data warehouse must be encrypted using FIPS 140-2 validated cryptographic modules, and the encryption keys must be managed by the customer with full auditability of key usage. Which Redshift encryption option should the data engineer choose to meet these requirements?

  1. AAmazon Redshift encryption with AWS KMS
  2. BClient-side encryption before loading data into Redshift
  3. CAmazon Redshift encryption with Hardware Security Module (HSM)
  4. DAmazon Redshift encryption with AWS-managed keys
Show answer & explanation

Correct answer: A. Amazon Redshift encryption with AWS KMS

Amazon Redshift encryption with AWS KMS uses customer-managed keys (CMKs) from AWS KMS, which are protected by FIPS 140-2 Level 2 validated hardware security modules. This option provides customer control over key usage and auditability through CloudTrail, satisfying the regulatory requirements.

Why the other options are wrong

  • B. Client-side encryption would require custom application logic and does not leverage Redshift's native encryption capabilities for data at rest within the cluster itself, making it less suitable for a data warehouse.
  • C. While Redshift offers a legacy HSM option, AWS KMS is the recommended and more integrated solution for customer-managed keys with FIPS validation and auditability.
  • D. AWS-managed keys (default encryption) do not provide customer control or auditability of key usage.

Redshift Encryption with KMS

Amazon Redshift encryption with AWS KMS protects data at rest in a Redshift cluster using customer-managed keys (CMKs) from AWS Key Management Service (KMS), which are backed by FIPS 140-2 Level 2 validated HSMs.

  • Encrypts data at rest in Redshift clusters.
  • Uses CMKs from AWS KMS.
  • Provides auditability of key usage via CloudTrail and customer control over key policies.

Memory trick: KMS Keys Keep Redshift Records Secure.

More Data Governance and Security questions