AWS Certified Machine Learning – SpecialtyData EngineeringMedium
A data engineering team is designing a new machine learning pipeline that will process sensitive customer data. They need to ensure that the data is encrypted both at rest and in transit, and that access to the encryption keys is tightly controlled and auditable. Which AWS service and encryption method should be prioritized to meet these requirements for data stored in Amazon S3?
- AAmazon S3 with Client-Side Encryption using a customer-provided key (CSE-C)
- BAmazon S3 with Server-Side Encryption using customer-provided keys (SSE-C)
- CAmazon S3 with Server-Side Encryption using S3-managed keys (SSE-S3)
- DAmazon S3 with Server-Side Encryption using AWS Key Management Service (SSE-KMS)
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon S3 with Server-Side Encryption using AWS Key Management Service (SSE-KMS)
SSE-KMS provides server-side encryption with AWS Key Management Service, allowing for centralized management, auditing, and fine-grained access control over the encryption keys, which is crucial for sensitive data and compliance requirements.
Why the other options are wrong
- A. CSE-C requires the application to manage encryption and decryption, which adds complexity and shifts responsibility away from AWS-managed services for key control.
- B. SSE-C requires the customer to manage and provide encryption keys, which decentralizes key management and lacks the auditing capabilities of KMS.
- C. SSE-S3 uses S3-managed keys, which does not provide the same level of key control and audibility as KMS for sensitive data.
SSE-KMS
Server-Side Encryption with AWS Key Management Service (SSE-KMS) is an encryption option for Amazon S3 that uses AWS KMS to manage encryption keys.
- Data is encrypted at rest and in transit.
- Provides centralized control and auditing of encryption keys.
- Integrates with AWS KMS for key policy management and access control.
Memory trick: KMS Keys Keep ML Data Secure and Controlled.