AWS Solutions Architect Handbook SAA-C03, from zero Bipin Singh
Security & identity

Encryption, keys, certificates and secrets

3 min readChapter 08 of 48By Bipin Singh

Domain 1 expects you to protect data at rest (stored) and in transit (moving over a network), and to choose the right key management service for the compliance requirement.

Encryption basics

AWS Key Management Service (KMS)

KMS creates and controls cryptographic keys and integrates with most AWS services.

Key type Who manages it Notes
AWS owned keys AWS, shared across accounts Invisible to you; used by default in some services
AWS managed keys (aws/s3, aws/rds…) AWS, in your account Free to store; automatic rotation; you can't change their policy
Customer managed keys You Full control: key policy, grants, rotation, enable/disable, deletion schedule; audit every use in CloudTrail

Key facts:

Key idea

"The company must control and audit the keys, and be able to disable them" → customer managed KMS key. "Dedicated, single-tenant hardware security modules under the company's exclusive control" → CloudHSM.

AWS CloudHSM

Dedicated hardware security modules in your VPC, validated to FIPS 140 Level 3. You manage the keys and users; AWS manages the hardware. Use when regulations require single-tenant HSMs, exclusive key control, or specific cryptographic operations. It's more operational work than KMS — choose it only when required. KMS can also use CloudHSM as a custom key store.

AWS Certificate Manager (ACM)

Exam cue: "certificate renewals keep being missed" → use ACM-issued certificates with automatic renewal.

Secrets: Secrets Manager vs Parameter Store

AWS Secrets Manager Systems Manager Parameter Store
Purpose Secrets: database passwords, API keys Configuration values and secrets (SecureString encrypted with KMS)
Automatic rotation Yes, built in (native for RDS, Aurora, Redshift, DocumentDB; Lambda for others) No built-in rotation
Cross-Region replication of secrets Yes No
Cost Per secret per month + API calls Standard parameters free; advanced parameters paid
Tip

"Rotate database credentials automatically" → Secrets Manager. "Store configuration values cheaply" → Parameter Store.

Encryption by service

Service At rest Notes
S3 SSE-S3 (default for new objects), SSE-KMS, DSSE-KMS, SSE-C, client-side Enforce TLS with a bucket policy condition aws:SecureTransport
EBS KMS; can enable encryption by default per Region Snapshots of encrypted volumes are encrypted
RDS / Aurora KMS; must be chosen at creation To encrypt an existing unencrypted DB: snapshot → copy snapshot with encryption → restore
DynamoDB Always encrypted; choose AWS owned, AWS managed or customer managed key
EFS KMS at creation; TLS for in-transit via mount helper
SQS / SNS / Kinesis Server-side encryption with KMS

In transit

Exam patterns

Bipin Singh
Written by Bipin Singh

Senior Full-Stack Engineer · AI & AWS. I design and run production systems on AWS — serverless, data and AI.

Work with me