AWS Certified Data Engineer – AssociateData Governance and SecurityMedium

A global financial services company is building a new data lake on Amazon S3 to store highly sensitive customer transaction data. Regulatory compliance dictates that all data at rest must be encrypted using FIPS 140-2 validated cryptographic modules, and the customer must have exclusive control over the encryption keys. Which AWS encryption option best meets these requirements?

  1. AClient-Side Encryption with an AWS Key Management Service (AWS KMS) provided key
  2. BServer-Side Encryption with Amazon S3-managed keys (SSE-S3)
  3. CServer-Side Encryption with AWS Key Management Service (SSE-KMS) and a Customer Managed Key (CMK)
  4. DServer-Side Encryption with Customer-provided keys (SSE-C)
Show answer & explanation

Correct answer: C. Server-Side Encryption with AWS Key Management Service (SSE-KMS) and a Customer Managed Key (CMK)

SSE-KMS with a Customer Managed Key (CMK) allows the customer to have exclusive control over the encryption keys, and AWS KMS uses FIPS 140-2 validated hardware security modules (HSMs). This combination directly addresses both regulatory requirements.

Why the other options are wrong

  • A. While client-side encryption can provide customer control, using a KMS-provided key for client-side encryption doesn't automatically guarantee FIPS 140-2 validation for the client-side encryption process itself, and SSE-KMS is typically preferred for at-rest encryption within S3.
  • B. SSE-S3 uses AWS-managed keys, which does not provide exclusive customer control over the keys.
  • D. SSE-C requires the customer to provide and manage their own encryption keys, but S3 handles encryption/decryption. It doesn't inherently guarantee FIPS 140-2 validation unless the customer's key management system ensures it.

SSE-KMS with CMK

Server-Side Encryption with AWS Key Management Service (KMS) and a Customer Managed Key (CMK) allows AWS to encrypt data at rest using keys managed within KMS, giving the customer full control over the encryption key's lifecycle and permissions.

  • Uses AWS KMS to manage encryption keys.
  • Customer has full control over CMKs (create, rotate, disable, delete).
  • KMS uses FIPS 140-2 validated hardware security modules (HSMs).

Memory trick: KMS Keeps Keys Secure for Customers.

More Data Governance and Security questions