Question 1 · choose 1
An application must encrypt 50 MB export files under a customer managed AWS KMS key before it sends them to a partner's storage outside AWS. The developer's first attempt passes each file to the KMS Encrypt operation and fails. The solution must make as few calls to AWS KMS as possible. What should the developer do?
- AAsk for a higher plaintext size limit for the Encrypt operation
- BCall GenerateDataKey, encrypt locally, and keep the encrypted data key
- CSplit each file into 4 KB chunks and call Encrypt once for every chunk
- DCall GenerateDataKeyWithoutPlaintext and encrypt the file with the returned key
Show the answer and why
AAsk for a higher plaintext size limit for the Encrypt operation
Incorrect
Encrypt accepts at most 4,096 bytes of plaintext. It is meant for small data such as keys and passwords, not for files.
BCall GenerateDataKey, encrypt locally, and keep the encrypted data key
Correct
This is envelope encryption: one call returns a plaintext data key for local encryption and a copy encrypted under the KMS key. The plaintext key is erased after use, and Decrypt recovers it later.
CSplit each file into 4 KB chunks and call Encrypt once for every chunk
Incorrect
This needs thousands of KMS calls per file. Data keys exist so that large data is encrypted outside AWS KMS with a single key request.
DCall GenerateDataKeyWithoutPlaintext and encrypt the file with the returned key
Incorrect
That operation returns only the encrypted copy of the data key, which cannot encrypt anything until it is decrypted with another call.
KMS keys encrypt small payloads; data keys from GenerateDataKey encrypt large data locally, with only the encrypted data key stored next to it.
AWS documentation