AWS Certified Data Engineer – AssociateData Governance and SecurityMedium
A large e-commerce platform uses Amazon Redshift for its analytics warehouse. Regulatory requirements dictate that all data in the Redshift cluster must be encrypted at rest. The security team also requires that the encryption keys be rotated annually and that key usage be auditable. Which encryption configuration should the data engineer choose for the Redshift cluster?
- ARedshift encryption with Hardware Security Module (HSM)
- BRedshift encryption with client-side encryption
- CRedshift encryption with Customer-managed keys (CMKs) in AWS KMS
- DRedshift encryption with AWS-managed keys (default)
Show answer & explanationAnswer & explanation
Correct answer: C. Redshift encryption with Customer-managed keys (CMKs) in AWS KMS
Using Customer-managed keys (CMKs) in AWS KMS for Redshift encryption allows the security team to control the key rotation schedule and provides an audit trail of key usage through AWS CloudTrail, meeting both requirements.
Why the other options are wrong
- A. Redshift does not natively support encryption with a customer-provided Hardware Security Module (HSM) directly; KMS is the standard for customer-controlled keys.
- B. Client-side encryption would require encrypting data before loading into Redshift, which is not a native Redshift encryption option and adds significant operational overhead.
- D. AWS-managed keys are rotated automatically by AWS, but the customer has no control over the rotation schedule or direct audit of key usage.
Redshift Encryption with CMKs
Encrypting Amazon Redshift clusters using Customer-managed keys (CMKs) in AWS KMS allows customers to manage and audit their encryption keys, providing greater control over data security.
- Data encrypted at rest in Redshift.
- Keys managed in AWS KMS by the customer.
- Supports manual or automatic key rotation.
- Key usage is auditable via CloudTrail.
Memory trick: KMS Keys Keep Redshift Secure