How to Apply Two Layers of Server-Side Encryption to S3 Uploads?

Ensure data encryption and masking.
Answer Correct answer: B — Use S3 dual-layer server-side encryption with AWS KMS keys (DSSE-KMS), which applies two independent server-side encryption layers to every object uploaded from the Lambda function.

A company uses a data lake that is based on an Amazon S3 bucket. To comply with regulations, the company must apply two layers of server-side encryption to files that are uploaded to the S3 bucket. The company wants to use an AWS Lambda function to apply the necessary encryption. Which solution will meet these requirements?

  1. Use both server-side encryption with AWS KMS keys (SSE-KMS) and the Amazon S3 Encryption Client.
  2. Use dual-layer server-side encryption with AWS KMS keys (DSSE-KMS). Correct Answer
  3. Use server-side encryption with customer-provided keys (SSE-C) before files are uploaded.
  4. Use server-side encryption with AWS KMS keys (SSE-KMS).

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests whether DSSE-KMS is distinguished from single-layer SSE-KMS, SSE-C, and the client-side S3 Encryption Client; the common trap is pairing SSE-KMS with the S3 Encryption Client and calling that two server-side layers.

Amazon S3 dual-layer server-side encryption with AWS KMS keys (DSSE-KMS) applies two independent encryption layers to each object and is the compliant choice when a data lake requires multilayer server-side encryption. The page confirms DSSE-KMS (B) as the answer and explains why SSE-KMS, SSE-C, and the S3 Encryption Client do not satisfy a two-layer server-side requirement.

Choosing A by assuming that SSE-KMS plus the Amazon S3 Encryption Client provides two server-side layers; the S3 Encryption Client performs client-side encryption, so only one layer is server-side.

Community Discussion (8 comments)

sdas1 👍 5
Answer is B
samadal 👍 3 Selected: B
The most crucial objective in the problem is "Two layers of server-side encryption must be applied." A: SSE-KMS is a single-layer server-side encryption that uses AWS KMS keys to encrypt data. The Amazon S3 Encryption Client performs client-side encryption, not server-side encryption. C: SSE-C is server-side encryption that uses customer-provided encryption keys to encrypt data. This does not provide two layers of encryption. D: SSE-KMS is a single-layer server-side encryption. It does not meet the encryption requirement of two layers of encryption. B: DSSE-KMS (dual-layer server-side encryption) uses two layers of encryption to encrypt data using keys managed by AWS KMS. The first layer is used to encrypt the data key, and the second layer is used to encrypt the actual data. This provides the two layers of server-side encryption required to meet compliance requirements.
Ja13 👍 2 Selected: B
B. Use dual-layer server-side encryption with AWS KMS keys (DSSE-KMS). Dual-layer server-side encryption with AWS KMS keys (DSSE-KMS) is specifically designed to apply two layers of encryption to meet regulatory compliance requirements. This ensures that each object stored in Amazon S3 is encrypted twice, providing the additional security layer that the company needs.
bakarys 👍 1 Selected: A
The solution that will meet these requirements is Option A: Use both server-side encryption with AWS KMS keys (SSE-KMS) and the Amazon S3 Encryption Client. This approach provides two layers of encryption. The first layer is the server-side encryption with AWS KMS keys (SSE-KMS), which encrypts the data at rest. The second layer is the client-side encryption using the Amazon S3 Encryption Client before the data is uploaded to S3. This way, the data is already encrypted when it arrives at S3 and then it gets encrypted again by S3, thus providing two layers of encryption. The other options are not as suitable: Option B: There’s no such thing as dual-layer server-side encryption with AWS KMS keys (DSSE-KMS). Option C: Server-side encryption with customer-provided keys (SSE-C) only provides one layer of encryption. Option D: Server-side encryption with AWS KMS keys (SSE-KMS) also only provides one layer of encryption
sdas1 👍 1
Using dual-layer server-side encryption with AWS Key Management Service (AWS KMS) keys (DSSE-KMS) applies two layers of encryption to objects when they are uploaded to Amazon S3. DSSE-KMS helps you more easily fulfill compliance standards that require you to apply multilayer encryption to your data and have full control of your encryption keys.
HunkyBunky 👍 2 Selected: B
I guess that right answer is - B https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingDSSEncryption.html
sdas1 👍 1
Answer is D
tgv 👍 1 Selected: B
https://docs.aws.amazon.com/AmazonS3/latest/userguide/specifying-dsse-encryption.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

DSSE-KMS is the Amazon S3 encryption mode that applies two independent layers of server-side encryption with AWS KMS keys to each object, which directly satisfies a regulatory requirement for two layers of server-side encryption on files uploaded to the data lake. Because Amazon S3 performs both encryption layers when the object is written, the Lambda function can use a standard PutObject operation without implementing client-side cryptographic logic or managing extra key material. This is the only listed option that is both server-side and dual-layer, and it is the AWS-recommended approach for compliance regimes that mandate multilayer server-side encryption. It also allows separate KMS keys to be used for each layer, giving the company full control over key policies and audit trails through AWS KMS.

Why the Other Options Are Wrong

Option A mixes SSE-KMS with the Amazon S3 Encryption Client, but the S3 Encryption Client encrypts data on the client side before it is sent to S3, so the result is one server-side layer plus one client-side layer, not the two server-side layers the regulation demands. Option C uses SSE-C, which is a single server-side layer based on customer-provided keys; it does not stack encryption layers, and it would force the Lambda function to pass the same customer key on every request. Option D uses SSE-KMS, which is the standard single-layer server-side encryption mode and therefore fails the explicit two-layer requirement. Only DSSE-KMS provides two layers entirely within Amazon S3's server-side encryption process.

Community Comment Notes

The community almost unanimously selected B, with samadal emphasizing that SSE-KMS is single-layer and noting that "The Amazon S3 Encryption Client performs client-side encryption, not server-side encryption." Ja13 echoed the design intent, explaining that DSSE-KMS is "specifically designed to apply two layers of encryption to meet regulatory compliance requirements." HunkyBunky and tgv both pointed to AWS documentation for DSSE encryption, reinforcing that this is a native S3 feature rather than a custom combination. A minority view from bakarys favored A, arguing that SSE-KMS plus the S3 Encryption Client offers two layers, but that reasoning ignores the word "server-side" in the requirement. sdas1 simply concluded "Answer is B," matching the majority and the AWS documentation.

Official Reference

Exam Strategy

When a question says 'two layers of server-side encryption,' eliminate any option that includes the Amazon S3 Encryption Client because that is client-side, and eliminate any single SSE mode such as SSE-KMS or SSE-C. DSSE-KMS is the only native S3 option that applies two server-side layers, regardless of whether the upload comes from Lambda or another client.

Frequently Asked Questions

Why is combining SSE-KMS with the S3 Encryption Client not two server-side layers?

The S3 Encryption Client encrypts data on the client side before upload, so only the SSE-KMS portion is server-side; the requirement demands two server-side encryption layers.

Can an AWS Lambda function use DSSE-KMS when uploading files to S3?

Yes. DSSE-KMS is applied by Amazon S3 at upload time, so the Lambda function can use a normal PutObject request and S3 transparently applies both server-side encryption layers.

Related Analysis

Practice All DEA-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DEA-C01 Practice Test →

← Back to DEA-C01 Study Guide