Question 1 · choose 1
A company stores regulated documents in Amazon S3. Auditors require that the company controls who can use the encryption key through its own key policy, can see every use of the key in AWS CloudTrail, and can disable the key at any time. Which encryption option meets all of these requirements?
- AServer-side encryption with Amazon S3 managed keys (SSE-S3)
- BServer-side encryption with the AWS managed key aws/s3 (SSE-KMS)
- CServer-side encryption with customer-provided keys (SSE-C)
- DServer-side encryption with a customer managed KMS key (SSE-KMS)
Show the answer and why
AServer-side encryption with Amazon S3 managed keys (SSE-S3)
Incorrect
With SSE-S3, Amazon S3 manages the keys. There is no key policy for the company to write and no key to disable.
BServer-side encryption with the AWS managed key aws/s3 (SSE-KMS)
Incorrect
Use of an AWS managed key appears in CloudTrail, but you cannot change its key policy or any of its properties, so you cannot disable it.
CServer-side encryption with customer-provided keys (SSE-C)
Incorrect
With SSE-C the company manages its keys outside AWS and sends them with each request. There is no KMS key policy, and the key's use is not tracked in AWS KMS.
DServer-side encryption with a customer managed KMS key (SSE-KMS)
Correct
A customer managed key is created and controlled by the company: it writes the key policy, can enable or disable the key, and every use is logged in CloudTrail.
Own key policy, audit trail and the power to disable: only a customer managed KMS key gives all three. AWS managed keys are auditable but not controllable.
AWS documentation