AWS Certified Data Engineer – AssociateData Governance and SecurityEasy
A financial services company is building a new data lake on AWS S3 to store highly sensitive customer financial records. Regulatory compliance mandates that all data at rest must be encrypted using customer-managed encryption keys (CMKs) from AWS Key Management Service (AWS KMS) and that these keys must be fully managed and controlled by the customer. Which S3 encryption method should the data engineer implement to meet these strict requirements?
- AServer-Side Encryption with Customer-Provided Keys (SSE-C)
- BServer-Side Encryption with AWS KMS keys (SSE-KMS)
- CServer-Side Encryption with Amazon S3-managed keys (SSE-S3)
- DClient-Side Encryption with AWS KMS managed keys
Show answer & explanationAnswer & explanation
Correct answer: B. Server-Side Encryption with AWS KMS keys (SSE-KMS)
SSE-KMS uses customer-managed keys (CMKs) stored in AWS KMS, which provides the customer with full control over the encryption keys, satisfying the regulatory requirement for customer management and control.
Why the other options are wrong
- A. SSE-C requires the customer to provide and manage their own encryption keys, which are not stored in AWS KMS, and does not leverage CMKs from AWS KMS.
- C. SSE-S3 uses keys fully managed by AWS, not customer-managed or controlled.
- D. Client-Side Encryption involves encrypting data before sending it to S3, but the question specifically asks for an S3 encryption method that uses CMKs from AWS KMS.
SSE-KMS
Server-Side Encryption with AWS KMS keys (SSE-KMS) is an S3 encryption option that uses customer-managed keys (CMKs) stored in AWS Key Management Service (AWS KMS) to encrypt data at rest.
- Uses CMKs from AWS KMS.
- Provides an audit trail of key usage.
- Gives customers control over encryption key permissions and rotation.
Memory trick: KMS Keys Keep Sensitive Secrets Safe.