AWS Certified Machine Learning – SpecialtyData EngineeringEasy

A data engineering team is designing a data lake for a new machine learning initiative. The data lake will store petabytes of raw sensor data, historical transaction logs, and customer interaction data. Due to compliance requirements, all data must be encrypted at rest. The team also needs to ensure that the encryption keys are managed centrally and that access to these keys is logged and audited. Which AWS encryption option for Amazon S3 best meets these requirements?

  1. AServer-Side Encryption with Amazon S3-managed keys (SSE-S3)
  2. BServer-Side Encryption with customer-provided keys (SSE-C)
  3. CClient-Side Encryption (CSE) with AWS KMS-managed keys
  4. DServer-Side Encryption with AWS Key Management Service (SSE-KMS)
Show answer & explanation

Correct answer: D. Server-Side Encryption with AWS Key Management Service (SSE-KMS)

SSE-KMS offers centralized key management, auditing, and integration with AWS KMS, which are explicit requirements for compliance and logging. SSE-S3 lacks centralized key management and auditing, SSE-C requires customers to manage their own keys, and CSE adds complexity by requiring client-side encryption logic.

Why the other options are wrong

  • A. This option uses S3-managed keys, which do not provide the required centralized key management or auditing capabilities.
  • B. This option requires the customer to provide and manage their own encryption keys, which does not meet the requirement for centralized key management by AWS.
  • C. While this uses KMS, it requires client-side implementation of encryption, which adds operational overhead and is not the 'best' server-side option for this scenario.

SSE-KMS

Server-Side Encryption with AWS Key Management Service (SSE-KMS) uses AWS KMS to manage encryption keys for objects stored in Amazon S3, providing enhanced security controls and auditing.

  • Uses AWS KMS for key management.
  • Provides an audit trail of key usage.
  • Keys are centrally managed and rotated by KMS.
  • Data is encrypted at rest on S3 servers.

Memory trick: KMS Keeps Keys Securely Managed for S3.

More Data Engineering questions