AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A development team is building a new application that uses Amazon SQS for message queuing. The messages contain sensitive customer information and must be encrypted at rest. The team requires that the encryption keys are managed by a service that integrates with AWS CloudTrail for auditing key usage and offers centralized control over key policies. Which SQS encryption option should they choose?

  1. AClient-Side Encryption before sending messages to SQS
  2. BServer-Side Encryption with Amazon SQS-Managed Keys (SSE-SQS)
  3. CEnable SQS queue access policies to restrict message access
  4. DServer-Side Encryption with AWS Key Management Service (SSE-KMS)
Show answer & explanation

Correct answer: D. Server-Side Encryption with AWS Key Management Service (SSE-KMS)

SSE-KMS encrypts SQS messages using AWS KMS, which provides centralized control over key policies, integrates with CloudTrail for auditing, and allows for customer-managed keys (CMKs) or AWS-managed keys (AMKs) with these features, meeting the specific requirements.

Why the other options are wrong

  • A. Client-Side Encryption would require the application developer to manage encryption and keys, which moves away from the centralized control and CloudTrail auditing of key usage that AWS KMS provides.
  • B. SSE-SQS uses SQS-managed keys, which do not offer the same level of centralized control, auditing via CloudTrail for key usage, or key policy management as KMS.
  • C. SQS queue access policies control who can access the queue, but they do not provide encryption at rest or manage encryption keys with audit trails for key usage.

SQS SSE-KMS

Server-Side Encryption with AWS Key Management Service (SSE-KMS) for Amazon SQS encrypts messages at rest using KMS keys. It offers centralized key management, integrates with CloudTrail for auditing, and allows fine-grained access control over keys.

  • Encrypts SQS messages at rest.
  • Uses AWS KMS for key management.
  • Integrates with CloudTrail for key usage auditing.
  • Centralized control over key policies.

Memory trick: KMS keys for SQS messages, audited in CloudTrail, centrally managed.

More Security questions