Which S3 encryption type prevents third-party access to uploaded documents?
A developer is creating a new application that will give users the ability to upload documents to Amazon S3. The contents of the documents must not be accessible to any third party. Which type of encryption will meet this requirement?
Community Votes
80% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the understanding of AWS-managed encryption versus customer-managed encryption, highlighting that SSE-KMS provides the necessary access control and audit logging without the operational complexity of client-side encryption.
This question explores the best Amazon S3 encryption method to ensure uploaded documents remain inaccessible to third parties. Community consensus heavily favors Server-Side Encryption with AWS KMS keys (SSE-KMS) for its balance of strong security, IAM integration, and auditability via CloudTrail.
Many candidates choose client-side encryption (Option A), mistakenly believing that keeping the key entirely off AWS guarantees the highest security. However, this approach is overly complex and shifts the burden of key management entirely to the user.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
The core requirement is that the contents of the documents must not be accessible to any third party. While all options provide encryption, the question implicitly seeks the most practical and secure AWS-native solution.
Option C (SSE-KMS) is the correct answer because it leverages AWS Key Management Service (KMS) to manage the encryption keys. This provides a robust level of security where AWS handles the heavy lifting of key rotation and storage, but the developer retains control through IAM policies. Crucially, SSE-KMS integrates with AWS CloudTrail, allowing for detailed auditing of key usage, which is essential for compliance and security monitoring. As community members noted, this offers the best balance of security and manageability.
Option A (Client-side encryption with a Raw RSA key) is a strong contender and provides end-to-end encryption where the key never leaves the user's device. However, as highlighted by the community, this approach is overly complex for a standard document upload scenario. It requires the application to manage the encryption process entirely and places the burden of key management on the user. If the user loses the key, the data is unrecoverable. For most AWS-based applications, SSE-KMS is the recommended and more practical approach.
Option B (SSE-S3) uses S3-managed keys. While it provides basic encryption at rest, it lacks the granular access control and audit capabilities of KMS. You cannot define IAM policies that require the use of a specific KMS key, making it less secure from a governance perspective.
Option D (DSSE-KMS) applies two layers of encryption. While it offers the highest level of security, it is generally considered overkill for standard document storage and introduces unnecessary latency and cost.
Official Reference
Exam Strategy
When an exam question asks for a solution that balances security with manageability and auditability on AWS, lean towards services that integrate with IAM and CloudTrail, such as AWS KMS. Avoid overly complex or 'perfect' solutions like client-side encryption unless the scenario explicitly demands that the cloud provider must have zero access.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →