Which S3 encryption type prevents third-party access to uploaded documents?

A developer is creating a new application that will give users the ability to upload documents to Amazon S3. The contents of the documents must not be accessible to any third party. Which type of encryption will meet this requirement?

  1. Client-side encryption by using the S3 Encryption Client with a Raw RSA wrapping key that is stored on the user’s device
  2. Server-side encryption with S3 managed keys (SSE-S3)
  3. Server-side encryption with AWS KMS keys (SSE-KMS) Source Reference Answer
  4. Dual-layer server-side encryption with AWS KMS keys (DSSE-KMS)

Community Votes

C
80%
A
20%

80% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the understanding of AWS-managed encryption versus customer-managed encryption, highlighting that SSE-KMS provides the necessary access control and audit logging without the operational complexity of client-side encryption.

This question explores the best Amazon S3 encryption method to ensure uploaded documents remain inaccessible to third parties. Community consensus heavily favors Server-Side Encryption with AWS KMS keys (SSE-KMS) for its balance of strong security, IAM integration, and auditability via CloudTrail.

Many candidates choose client-side encryption (Option A), mistakenly believing that keeping the key entirely off AWS guarantees the highest security. However, this approach is overly complex and shifts the burden of key management entirely to the user.

Community Discussion (4 comments)

Dadasar 👍 1 Selected: C
Protege os dados com chaves gerenciadas pelo AWS KMS, oferecendo um nível extra de controle e auditoria sobre as chaves.Além disso, o SSE-KMS permite logs detalhados de acessos e tentativas de descriptografia no AWS CloudTrail. A. Errado, pois essa abordagem exige que os usuários gerenciem suas próprias chaves. Se um usuário perder a chave, os dados não poderão ser recuperados. Além disso, essa abordagem não aproveita os recursos de controle de acesso e auditoria do AWS KMS. B. Errado, pois o SSE-S3 usa chaves gerenciadas pelo próprio Amazon S3 e não permite controle detalhado sobre quem pode descriptografar os dados. D. Errado, porque o DSSE-KMS (Dual-layer Server-Side Encryption with AWS KMS) é mais adequado para FINRA e CJIS
LingZ 👍 1 Selected: A
A. Client-side encryption using the S3 Encryption Client with a Raw RSA key: This is the correct answer because it ensures complete end-to-end protection. Here's why: The document is encrypted on the user's device before transmission The encryption key never leaves the user's control Even AWS cannot access the unencrypted contents The data remains protected throughout its entire lifecycle
italiancloud2025 👍 1 Selected: C
Es una solución robusta y administrativamente sencilla, sin la complejidad del cifrado del lado del cliente (opción A) y con un nivel de seguridad superior al de SSE-S3 (opción B). La opción D implicaría una doble capa de cifrado innecesaria para este caso.
Arad 👍 2 Selected: C
C is the correct answer. A is too complex. B is not the most secure way as there's no integration with IAM for access control policies specific to the key. D is overkill.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

The core requirement is that the contents of the documents must not be accessible to any third party. While all options provide encryption, the question implicitly seeks the most practical and secure AWS-native solution.

Option C (SSE-KMS) is the correct answer because it leverages AWS Key Management Service (KMS) to manage the encryption keys. This provides a robust level of security where AWS handles the heavy lifting of key rotation and storage, but the developer retains control through IAM policies. Crucially, SSE-KMS integrates with AWS CloudTrail, allowing for detailed auditing of key usage, which is essential for compliance and security monitoring. As community members noted, this offers the best balance of security and manageability.

Option A (Client-side encryption with a Raw RSA key) is a strong contender and provides end-to-end encryption where the key never leaves the user's device. However, as highlighted by the community, this approach is overly complex for a standard document upload scenario. It requires the application to manage the encryption process entirely and places the burden of key management on the user. If the user loses the key, the data is unrecoverable. For most AWS-based applications, SSE-KMS is the recommended and more practical approach.

Option B (SSE-S3) uses S3-managed keys. While it provides basic encryption at rest, it lacks the granular access control and audit capabilities of KMS. You cannot define IAM policies that require the use of a specific KMS key, making it less secure from a governance perspective.

Option D (DSSE-KMS) applies two layers of encryption. While it offers the highest level of security, it is generally considered overkill for standard document storage and introduces unnecessary latency and cost.

Official Reference

Exam Strategy

When an exam question asks for a solution that balances security with manageability and auditability on AWS, lean towards services that integrate with IAM and CloudTrail, such as AWS KMS. Avoid overly complex or 'perfect' solutions like client-side encryption unless the scenario explicitly demands that the cloud provider must have zero access.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide