Encryption, keys, certificates and secrets
Domain 1 expects you to protect data at rest (stored) and in transit (moving over a network), and to choose the right key management service for the compliance requirement.
Encryption basics
- At rest — data on disks, in buckets, in databases and backups.
- In transit — data moving between clients and services, protected with TLS.
- Envelope encryption — data is encrypted with a data key; the data key is itself encrypted with a key-encryption key held in KMS. This is how most AWS services encrypt large data efficiently.
AWS Key Management Service (KMS)
KMS creates and controls cryptographic keys and integrates with most AWS services.
| Key type | Who manages it | Notes |
|---|---|---|
| AWS owned keys | AWS, shared across accounts | Invisible to you; used by default in some services |
AWS managed keys (aws/s3, aws/rds…) |
AWS, in your account | Free to store; automatic rotation; you can't change their policy |
| Customer managed keys | You | Full control: key policy, grants, rotation, enable/disable, deletion schedule; audit every use in CloudTrail |
Key facts:
- Every KMS key has a key policy (a resource-based policy). Access requires the key policy to allow it — directly or by delegating to IAM.
- Automatic rotation for customer managed keys is optional (yearly by default); old key material is kept so existing data still decrypts.
- KMS keys are Regional. Multi-Region keys share key material across Regions for cross-Region encryption/decryption (e.g. global tables, DR).
- The KMS
EncryptAPI handles only small payloads (up to 4 KB) — larger data uses envelope encryption viaGenerateDataKey. - Deleting a key requires a waiting period of 7–30 days — deleted keys make data unrecoverable.
- High request rates can hit KMS request quotas; S3 Bucket Keys reduce KMS calls for SSE-KMS.
"The company must control and audit the keys, and be able to disable them" → customer managed KMS key. "Dedicated, single-tenant hardware security modules under the company's exclusive control" → CloudHSM.
AWS CloudHSM
Dedicated hardware security modules in your VPC, validated to FIPS 140 Level 3. You manage the keys and users; AWS manages the hardware. Use when regulations require single-tenant HSMs, exclusive key control, or specific cryptographic operations. It's more operational work than KMS — choose it only when required. KMS can also use CloudHSM as a custom key store.
AWS Certificate Manager (ACM)
- Issues free public TLS certificates and renews them automatically.
- Deploys certificates to integrated services: Elastic Load Balancing, CloudFront, API Gateway, and others.
- Certificates for CloudFront must be in us-east-1 (N. Virginia); for ALBs, in the same Region as the load balancer.
- You can import third-party certificates (but then you handle renewal).
- Private certificates via AWS Private CA.
Exam cue: "certificate renewals keep being missed" → use ACM-issued certificates with automatic renewal.
Secrets: Secrets Manager vs Parameter Store
| AWS Secrets Manager | Systems Manager Parameter Store | |
|---|---|---|
| Purpose | Secrets: database passwords, API keys | Configuration values and secrets (SecureString encrypted with KMS) |
| Automatic rotation | Yes, built in (native for RDS, Aurora, Redshift, DocumentDB; Lambda for others) | No built-in rotation |
| Cross-Region replication of secrets | Yes | No |
| Cost | Per secret per month + API calls | Standard parameters free; advanced parameters paid |
"Rotate database credentials automatically" → Secrets Manager. "Store configuration values cheaply" → Parameter Store.
Encryption by service
| Service | At rest | Notes |
|---|---|---|
| S3 | SSE-S3 (default for new objects), SSE-KMS, DSSE-KMS, SSE-C, client-side | Enforce TLS with a bucket policy condition aws:SecureTransport |
| EBS | KMS; can enable encryption by default per Region | Snapshots of encrypted volumes are encrypted |
| RDS / Aurora | KMS; must be chosen at creation | To encrypt an existing unencrypted DB: snapshot → copy snapshot with encryption → restore |
| DynamoDB | Always encrypted; choose AWS owned, AWS managed or customer managed key | |
| EFS | KMS at creation; TLS for in-transit via mount helper | |
| SQS / SNS / Kinesis | Server-side encryption with KMS |
In transit
- Use HTTPS/TLS endpoints for AWS APIs (default).
- Terminate TLS at the load balancer with ACM certificates; re-encrypt to targets if end-to-end encryption is required.
- Site-to-Site VPN encrypts traffic over the internet; Direct Connect is not encrypted by default — add a VPN over it or use MACsec on supported connections.
Exam patterns
- "Encrypt data at rest with keys the company can rotate and audit" → customer managed KMS key.
- "An existing RDS instance is unencrypted and must be encrypted" → snapshot, encrypted copy, restore.
- "Enforce encryption for every object uploaded to a bucket" → default bucket encryption plus bucket policy denying non-compliant uploads.
- "Store and rotate third-party API keys" → Secrets Manager.