Uni Cert / SAA-C03 / Data encryption and secrets

Data encryption and secrets

KMS keys, encryption at rest and in transit, Secrets Manager, and S3 security controls.

Estimated reading: ~25 min

Protect data at rest and in transit

SAA-C03 expects you to choose where encryption happens, who holds keys, and how applications fetch secrets — without breaking performance or operability.

Encryption in transit

  • TLS everywhere — ALB/CloudFront/API Gateway terminate HTTPS with ACM certificates (free for AWS-integrated services).
  • Client-side encryption — you encrypt before upload (extra control, more app burden).
  • VPC endpoints + TLS — traffic to AWS APIs stays on private AWS network; still use HTTPS for defense in depth.

Encryption at rest — AWS KMS

AWS Key Management Service (KMS) manages encryption keys:

  • AWS managed keys — service-owned (e.g. aws/s3); easy, less control.
  • Customer managed keys (CMK) — you define policy, rotation, cross-account use.
  • Envelope encryption — data key encrypts bulk data; CMK encrypts data key.

Exam patterns:

  • S3 bucket default encryption with SSE-KMS for audit trail via CloudTrail.
  • EBS volumes encrypted by default in most accounts; snapshot sharing requires key policy consideration.
  • RDS/Aurora encryption at rest chosen at creation; use CMK for compliance.

Key policies vs IAM policies

KMS evaluates key policy (required) and IAM policies. Cross-account access needs allow on both the key policy and the IAM role in the consuming account.

Amazon S3 security essentials

  • Block Public Access — account and bucket level; turn on unless you truly need public objects.
  • Bucket policies — resource-based; useful for cross-account and conditional access (aws:SecureTransport).
  • Object Lock / versioning — WORM compliance and ransomware recovery.
  • S3 Object Lambda — inspect/transform on GET (advanced).

SSE-S3 vs SSE-KMS vs SSE-C — exam loves SSE-KMS for audit + key control; SSE-S3 for simplicity.

Secrets Manager vs Parameter Store

Secrets ManagerSystems Manager Parameter Store
RotationNative for RDS, Redshift, etc.Manual / Lambda rotation
CostPer secret + API callsStandard params free tier
Use caseDB credentials, API keysConfig, non-rotating values

Never hardcode secrets in AMIs, user data, or Git. Lambda/ECS/EKS pull secrets at runtime via IAM role.

Data classification workflow

  1. Classify data (public, internal, confidential, regulated).
  2. Choose storage (S3 tier, RDS, DynamoDB) with matching encryption & backup.
  3. Restrict access via IAM + bucket policy + KMS key policy.
  4. Log access — CloudTrail data events for S3 objects when needed.

Exam traps

  • Enabling encryption on existing unencrypted RDS — often requires snapshot copy (read exam choices carefully).
  • Sharing encrypted snapshots across accounts — KMS key policy must allow target account.
  • "Encrypt with custom key" in multi-service design — watch region (KMS keys are regional).

Official reference

SAA-C03 exam guide — data security controls.

Official reference: AWS documentation

Chat with G.U.S.

Share suggestions to improve the site or any complaints. We use your feedback to make unigrat.com better.

Hi, I am G.U.S. — Growth Upgrade Suggestions.

Share your suggestions or complaints below.