A data engineering team is building an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another. The security team mandates that both read and write operations use a customer-managed AWS KMS key so they can audit key usage. Which configuration should the data engineer apply to the Glue job to meet this requirement?
A Glue Security configuration allows you to specify a KMS key for S3 encryption, which Glue uses when reading from and writing to S3. By attaching this configuration to the job, all data access uses the specified customer-managed key, satisfying the audit requirement. This is the intended mechanism for controlling encryption in Glue jobs.
Why this answer
The correct approach is to use an AWS Glue Security configuration that specifies the customer-managed KMS key for S3 encryption. This configuration is applied at the job level and ensures that Glue uses the key for both reading and writing data. It provides a centralized way to enforce encryption and enables auditing of key usage.
Other methods like bucket policies or default encryption do not guarantee that the Glue job will use the specified key for all operations.
Exam trap
The trap here is assuming that S3 bucket default encryption or bucket policies alone will force AWS Glue to use a specific customer-managed KMS key for both reads and writes.