AWS Certified Data Engineer – AssociateData Governance and SecurityHard
A data engineer is designing a data lake solution on AWS S3 for a company that handles sensitive customer data. The company's security policy mandates that all data written to S3 must be encrypted using keys that are stored in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which AWS service allows the company to meet this stringent key management requirement for S3 encryption?
- AAWS CloudHSM
- BServer-Side Encryption with Customer-provided keys (SSE-C)
- CServer-Side Encryption with S3-managed keys (SSE-S3)
- DAWS Key Management Service (KMS) with default CMKs
Show answer & explanationAnswer & explanation
Correct answer: A. AWS CloudHSM
AWS CloudHSM provides dedicated, single-tenant hardware security modules (HSMs) that are FIPS 140-2 Level 3 validated. This allows customers to generate and use their own encryption keys within these HSMs, directly meeting the stringent requirement of keys being stored in a FIPS 140-2 Level 3 validated HSM and controlled by the customer.
Why the other options are wrong
- B. SSE-C requires the customer to provide and manage their own encryption keys, but doesn't inherently guarantee FIPS 140-2 Level 3 compliance for the key storage without a separate, custom HSM solution.
- C. SSE-S3 uses AWS-managed keys and does not provide customer control over key storage location or FIPS validation level.
- D. AWS KMS provides FIPS 140-2 Level 2 validated HSMs by default, which does not meet the Level 3 requirement.
AWS CloudHSM
AWS CloudHSM is a cloud-based hardware security module (HSM) service that enables you to easily generate and use your own encryption keys on FIPS 140-2 Level 3 validated hardware.
- Dedicated, single-tenant HSMs.
- FIPS 140-2 Level 3 validated.
- Customer controls key generation and storage.
- Integrates with S3 for encryption.
Memory trick: CloudHSM for Highest Key Standards