AWS Certified Data Engineer – AssociateData Governance and SecurityHard

A data analytics team is building a new application that will store sensitive customer transaction data in an Amazon S3 data lake. The company's security policy dictates that encryption keys for this data must be stored in a FIPS 140-2 Level 3 validated hardware security module (HSM) and that the customer must have exclusive control over the cryptographic operations. The data engineer needs to select an S3 encryption method that meets these stringent requirements. Which option provides the highest level of key control and hardware security for S3 data?

  1. AServer-Side Encryption with Customer-Provided Keys (SSE-C)
  2. BServer-Side Encryption with Amazon S3-managed keys (SSE-S3)
  3. CServer-Side Encryption with AWS KMS keys (SSE-KMS)
  4. DClient-Side Encryption with a client-side master key stored in AWS CloudHSM
Show answer & explanation

Correct answer: D. Client-Side Encryption with a client-side master key stored in AWS CloudHSM

Client-Side Encryption (CSE) combined with a client-side master key stored in AWS CloudHSM offers the highest level of control and FIPS 140-2 Level 3 compliance. The customer manages the encryption and decryption process before data leaves their control, and the master key is protected within a dedicated, customer-controlled HSM.

Why the other options are wrong

  • A. SSE-C requires the customer to provide and manage keys, but S3 performs the encryption/decryption server-side, and the keys are not stored in a FIPS 140-2 Level 3 validated HSM under exclusive customer control, nor does it involve client-side encryption.
  • B. SSE-S3 uses AWS-managed keys and doesn't provide customer control over keys or FIPS 140-2 Level 3 HSMs.
  • C. SSE-KMS uses KMS keys, which are protected by FIPS 140-2 Level 2 validated HSMs, but the customer does not have exclusive control over the HSM itself, only the key's permissions.

Client-Side Encryption with CloudHSM

Client-Side Encryption (CSE) with keys stored in AWS CloudHSM involves encrypting data on the client side before uploading to S3, using master keys managed by the customer within their dedicated FIPS 140-2 Level 3 validated CloudHSM.

  • Data encrypted before leaving client control.
  • Master keys stored in customer-controlled AWS CloudHSM.
  • Provides FIPS 140-2 Level 3 compliance and exclusive key control.

Memory trick: CloudHSM Client Keys Control Cryptography Completely.

More Data Governance and Security questions