Protect data at rest and in transit
SAA-C03 expects you to choose where encryption happens, who holds keys, and how applications fetch secrets — without breaking performance or operability.
Encryption in transit
- TLS everywhere — ALB/CloudFront/API Gateway terminate HTTPS with ACM certificates (free for AWS-integrated services).
- Client-side encryption — you encrypt before upload (extra control, more app burden).
- VPC endpoints + TLS — traffic to AWS APIs stays on private AWS network; still use HTTPS for defense in depth.
Encryption at rest — AWS KMS
AWS Key Management Service (KMS) manages encryption keys:
- AWS managed keys — service-owned (e.g.
aws/s3); easy, less control. - Customer managed keys (CMK) — you define policy, rotation, cross-account use.
- Envelope encryption — data key encrypts bulk data; CMK encrypts data key.
Exam patterns:
- S3 bucket default encryption with SSE-KMS for audit trail via CloudTrail.
- EBS volumes encrypted by default in most accounts; snapshot sharing requires key policy consideration.
- RDS/Aurora encryption at rest chosen at creation; use CMK for compliance.
Key policies vs IAM policies
KMS evaluates key policy (required) and IAM policies. Cross-account access needs allow on both the key policy and the IAM role in the consuming account.
Amazon S3 security essentials
- Block Public Access — account and bucket level; turn on unless you truly need public objects.
- Bucket policies — resource-based; useful for cross-account and conditional access (
aws:SecureTransport). - Object Lock / versioning — WORM compliance and ransomware recovery.
- S3 Object Lambda — inspect/transform on GET (advanced).
SSE-S3 vs SSE-KMS vs SSE-C — exam loves SSE-KMS for audit + key control; SSE-S3 for simplicity.
Secrets Manager vs Parameter Store
| Secrets Manager | Systems Manager Parameter Store | |
|---|---|---|
| Rotation | Native for RDS, Redshift, etc. | Manual / Lambda rotation |
| Cost | Per secret + API calls | Standard params free tier |
| Use case | DB credentials, API keys | Config, non-rotating values |
Never hardcode secrets in AMIs, user data, or Git. Lambda/ECS/EKS pull secrets at runtime via IAM role.
Data classification workflow
- Classify data (public, internal, confidential, regulated).
- Choose storage (S3 tier, RDS, DynamoDB) with matching encryption & backup.
- Restrict access via IAM + bucket policy + KMS key policy.
- Log access — CloudTrail data events for S3 objects when needed.
Exam traps
- Enabling encryption on existing unencrypted RDS — often requires snapshot copy (read exam choices carefully).
- Sharing encrypted snapshots across accounts — KMS key policy must allow target account.
- "Encrypt with custom key" in multi-service design — watch region (KMS keys are regional).
Official reference
SAA-C03 exam guide — data security controls.