A company stores sensitive customer data in an Amazon S3 bucket. The security team wants to ensure that all data is encrypted at rest using keys that the company controls, including the ability to rotate keys and audit key usage. They also want to minimize operational overhead for key management. Which solution meets these requirements?
SSE-KMS with customer managed keys gives the company control over the KMS key, including key policies, rotation, and auditing via AWS CloudTrail. It integrates natively with S3, so no application changes are needed, minimizing operational overhead. This meets the requirements for customer-controlled keys, rotation, and auditability while leveraging AWS-managed infrastructure.
Why this answer
SSE-KMS with customer managed keys allows the company to control the KMS keys, configure automatic rotation, and audit key usage through CloudTrail. It is a native S3 feature, so no application changes are needed. SSE-S3 does not give key control, SSE-C requires the customer to manage keys per request, and client-side encryption adds significant operational burden.
Exam trap
The trap here is assuming that any server-side encryption provides customer-controlled keys and auditability.