How to Apply Two Layers of Server-Side Encryption to S3 Uploads?
A company uses a data lake that is based on an Amazon S3 bucket. To comply with regulations, the company must apply two layers of server-side encryption to files that are uploaded to the S3 bucket. The company wants to use an AWS Lambda function to apply the necessary encryption. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests whether DSSE-KMS is distinguished from single-layer SSE-KMS, SSE-C, and the client-side S3 Encryption Client; the common trap is pairing SSE-KMS with the S3 Encryption Client and calling that two server-side layers.
Amazon S3 dual-layer server-side encryption with AWS KMS keys (DSSE-KMS) applies two independent encryption layers to each object and is the compliant choice when a data lake requires multilayer server-side encryption. The page confirms DSSE-KMS (B) as the answer and explains why SSE-KMS, SSE-C, and the S3 Encryption Client do not satisfy a two-layer server-side requirement.
Choosing A by assuming that SSE-KMS plus the Amazon S3 Encryption Client provides two server-side layers; the S3 Encryption Client performs client-side encryption, so only one layer is server-side.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
DSSE-KMS is the Amazon S3 encryption mode that applies two independent layers of server-side encryption with AWS KMS keys to each object, which directly satisfies a regulatory requirement for two layers of server-side encryption on files uploaded to the data lake. Because Amazon S3 performs both encryption layers when the object is written, the Lambda function can use a standard PutObject operation without implementing client-side cryptographic logic or managing extra key material. This is the only listed option that is both server-side and dual-layer, and it is the AWS-recommended approach for compliance regimes that mandate multilayer server-side encryption. It also allows separate KMS keys to be used for each layer, giving the company full control over key policies and audit trails through AWS KMS.Why the Other Options Are Wrong
Option A mixes SSE-KMS with the Amazon S3 Encryption Client, but the S3 Encryption Client encrypts data on the client side before it is sent to S3, so the result is one server-side layer plus one client-side layer, not the two server-side layers the regulation demands. Option C uses SSE-C, which is a single server-side layer based on customer-provided keys; it does not stack encryption layers, and it would force the Lambda function to pass the same customer key on every request. Option D uses SSE-KMS, which is the standard single-layer server-side encryption mode and therefore fails the explicit two-layer requirement. Only DSSE-KMS provides two layers entirely within Amazon S3's server-side encryption process.Community Comment Notes
The community almost unanimously selected B, with samadal emphasizing that SSE-KMS is single-layer and noting that "The Amazon S3 Encryption Client performs client-side encryption, not server-side encryption." Ja13 echoed the design intent, explaining that DSSE-KMS is "specifically designed to apply two layers of encryption to meet regulatory compliance requirements." HunkyBunky and tgv both pointed to AWS documentation for DSSE encryption, reinforcing that this is a native S3 feature rather than a custom combination. A minority view from bakarys favored A, arguing that SSE-KMS plus the S3 Encryption Client offers two layers, but that reasoning ignores the word "server-side" in the requirement. sdas1 simply concluded "Answer is B," matching the majority and the AWS documentation.Official Reference
Exam Strategy
When a question says 'two layers of server-side encryption,' eliminate any option that includes the Amazon S3 Encryption Client because that is client-side, and eliminate any single SSE mode such as SSE-KMS or SSE-C. DSSE-KMS is the only native S3 option that applies two server-side layers, regardless of whether the upload comes from Lambda or another client.
Frequently Asked Questions
Why is combining SSE-KMS with the S3 Encryption Client not two server-side layers?
The S3 Encryption Client encrypts data on the client side before upload, so only the SSE-KMS portion is server-side; the requirement demands two server-side encryption layers.
Can an AWS Lambda function use DSSE-KMS when uploading files to S3?
Yes. DSSE-KMS is applied by Amazon S3 at upload time, so the Lambda function can use a normal PutObject request and S3 transparently applies both server-side encryption layers.
Related Analysis
Practice All DEA-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DEA-C01 Practice Test →