AWS Certified Developer – Associate (DVA-C02)SecurityHard

A developer is deploying a new microservice to AWS Fargate. The microservice needs to store temporary, sensitive data in its ephemeral storage. The company's compliance requirements mandate that all data at rest, including ephemeral storage, must be encrypted using customer-managed keys (CMKs) from AWS Key Management Service (KMS). How can the developer ensure that the Fargate task's ephemeral storage is encrypted with a KMS CMK?

  1. AConfigure the Fargate task definition to specify an EBS volume encrypted with a KMS CMK.
  2. BMount an Amazon EFS file system encrypted with a KMS CMK to the Fargate task.
  3. CSpecify a KMS CMK in the Fargate task definition's `ephemeralStorage` configuration.
  4. DEnable Fargate's built-in ephemeral storage encryption, which automatically uses a KMS CMK.
Show answer & explanation

Correct answer: C. Specify a KMS CMK in the Fargate task definition's `ephemeralStorage` configuration.

AWS Fargate ephemeral storage can be encrypted using a KMS CMK by directly specifying the `kmsKeyId` in the `ephemeralStorage` section of the Fargate task definition. This ensures compliance with the customer-managed key requirement for ephemeral data.

Why the other options are wrong

  • A. Fargate tasks use ephemeral storage by default; attaching EBS volumes is not the primary way to encrypt *ephemeral* storage, and while EBS can use CMKs, it's not the ephemeral storage of the task itself.
  • B. While EFS can be encrypted with KMS CMKs, it's a network file system, not the *ephemeral storage* directly allocated to the Fargate task. Using EFS for temporary data adds complexity and might not meet the 'ephemeral storage' specific requirement.
  • D. Fargate's ephemeral storage is encrypted by default with AWS-managed keys. To use a *customer-managed key*, explicit configuration in the task definition is required, not automatic.

Fargate Ephemeral Storage Encryption with CMK

AWS Fargate allows encryption of its ephemeral task storage using a Customer Managed Key (CMK) from AWS KMS. This is configured directly within the task definition by specifying a `kmsKeyId` for the `ephemeralStorage`.

  • Encrypts Fargate task's ephemeral storage.
  • Uses AWS KMS Customer Managed Keys (CMK).
  • Configured in the task definition.
  • Ensures compliance for sensitive temporary data.

Memory trick: Fargate ephemeral storage takes its KMS CMK directly from the task definition.

More Security questions