AWS Certified Data Engineer – AssociateData Governance and SecurityHard

A data engineer is designing a data lake solution on AWS S3 for a company that handles sensitive customer data. The company's security policy mandates that all data written to S3 must be encrypted using keys that are stored in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which AWS service allows the company to meet this stringent key management requirement for S3 encryption?

  1. AAWS CloudHSM
  2. BServer-Side Encryption with Customer-provided keys (SSE-C)
  3. CServer-Side Encryption with S3-managed keys (SSE-S3)
  4. DAWS Key Management Service (KMS) with default CMKs
Show answer & explanation

Correct answer: A. AWS CloudHSM

AWS CloudHSM provides dedicated, single-tenant hardware security modules (HSMs) that are FIPS 140-2 Level 3 validated. This allows customers to generate and use their own encryption keys within these HSMs, directly meeting the stringent requirement of keys being stored in a FIPS 140-2 Level 3 validated HSM and controlled by the customer.

Why the other options are wrong

  • B. SSE-C requires the customer to provide and manage their own encryption keys, but doesn't inherently guarantee FIPS 140-2 Level 3 compliance for the key storage without a separate, custom HSM solution.
  • C. SSE-S3 uses AWS-managed keys and does not provide customer control over key storage location or FIPS validation level.
  • D. AWS KMS provides FIPS 140-2 Level 2 validated HSMs by default, which does not meet the Level 3 requirement.

AWS CloudHSM

AWS CloudHSM is a cloud-based hardware security module (HSM) service that enables you to easily generate and use your own encryption keys on FIPS 140-2 Level 3 validated hardware.

  • Dedicated, single-tenant HSMs.
  • FIPS 140-2 Level 3 validated.
  • Customer controls key generation and storage.
  • Integrates with S3 for encryption.

Memory trick: CloudHSM for Highest Key Standards

More Data Governance and Security questions