An application stores sensitive files in Amazon S3 and must encrypt data at rest. Company policy requires an audit trail that shows when the AWS KMS key was used and which principal used it. Which server-side encryption option satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Server-side encryption with AWS KMS managed keys (SSE-KMS).
Why this is the answer
SSE-KMS (Server-Side Encryption with AWS KMS managed keys) is the correct choice because it integrates with AWS Key Management Service (KMS), which provides an audit trail through AWS CloudTrail. CloudTrail logs all API calls made to KMS, including when a key is used for encryption or decryption, and identifies the principal that made the request. This directly satisfies the company's requirement for an audit trail showing key usage and the principal. SSE-S3 uses S3-managed keys and does not provide an audit trail for key usage. SSE-C uses customer-provided keys, meaning AWS does not manage the keys or provide an audit trail for their usage. Server-side encryption with customer-managed keys outside of KMS is not a standard S3 encryption option and would not integrate with AWS services for an audit trail.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed