AWS Certified Data Engineer – AssociateData Governance and SecurityEasy

A financial services company stores highly sensitive customer transaction data in an Amazon S3 bucket. Compliance regulations mandate that all data at rest must be encrypted using encryption keys that the company controls and manages independently. Which S3 encryption option should the data engineer implement to meet this requirement?

  1. AServer-Side Encryption with Customer-provided keys (SSE-C)
  2. BClient-Side Encryption with S3 managed keys
  3. CServer-Side Encryption with Amazon S3-managed keys (SSE-S3)
  4. DServer-Side Encryption with AWS Key Management Service (SSE-KMS)
Show answer & explanation

Correct answer: D. Server-Side Encryption with AWS Key Management Service (SSE-KMS)

SSE-KMS allows customers to use AWS KMS to manage encryption keys, providing more control over the keys than SSE-S3, while still benefiting from AWS's key management infrastructure. This meets the requirement of the company controlling and managing its keys independently.

Why the other options are wrong

  • A. SSE-C requires the customer to provide and manage their own encryption keys directly, which can be complex and does not leverage AWS's key management service for key control.
  • B. Client-Side Encryption involves encrypting data before uploading to S3, and 'S3 managed keys' for client-side encryption is not a standard S3 option.
  • C. SSE-S3 uses keys managed entirely by S3, not controlled independently by the customer.

SSE-KMS

Server-Side Encryption with AWS Key Management Service (SSE-KMS) uses AWS KMS to manage the encryption keys, providing customers with audit trails and fine-grained control over key usage.

  • Data encrypted at rest on S3.
  • Keys managed by AWS KMS.
  • Customer retains control over key policies and audit trails.

Memory trick: KMS Keeps My Secrets Safe

More Data Governance and Security questions