AWS Certified Developer – Associate (DVA-C02)SecurityEasy
A developer is building a new application that will use Amazon S3 to store sensitive customer data. The data must be encrypted at rest, and the encryption keys must be rotated automatically without manual intervention. The development team wants to ensure that AWS manages the encryption keys entirely. Which encryption option should the developer choose?
- AServer-Side Encryption with AWS Key Management Service (SSE-KMS)
- BServer-Side Encryption with Customer-Provided Keys (SSE-C)
- CServer-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
- DClient-Side Encryption
Show answer & explanationAnswer & explanation
Correct answer: C. Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
SSE-S3 uses keys managed entirely by AWS, providing automatic rotation and server-side encryption without customer involvement in key management. This aligns with the requirement for AWS to manage keys entirely and for automatic rotation.
Why the other options are wrong
- A. SSE-KMS allows for more control over keys via KMS and requires a KMS key ID, but the question specifically asks for AWS to manage keys 'entirely' and for automatic rotation without manual intervention, which SSE-S3 simplifies further by abstracting KMS key management from the customer.
- B. SSE-C requires the customer to provide and manage their own encryption keys, which contradicts the requirement for AWS to manage keys.
- D. Client-Side Encryption requires the client application to encrypt data before sending it to S3, which means the customer manages the encryption process and keys, not AWS.
S3 SSE-S3
Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3) encrypts S3 objects using keys managed entirely by AWS. S3 handles key creation, rotation, and protection.
- AWS manages the encryption keys.
- Automatic key rotation.
- No customer management of keys required.
- Encrypts data at rest.
Memory trick: S3 Encrypts Safely, Customer Keys or AWS Keys Securely.