How to Encrypt a Large PDF File Using AWS KMS GenerateDataKey?
A developer is writing an application that will retrieve sensitive data from a third-party system. The application will format the data into a PDF file. The PDF file could be more than 1 MB. The application will encrypt the data to disk by using AWS Key Management Service (AWS KMS). The application will decrypt the file when a user requests to download it. The retrieval and formatting portions of the application are complete. The developer needs to use the GenerateDataKey API to encrypt the PDF file so that the PDF file can be decrypted later. The developer needs to use an AWS KMS symmetric customer managed key for encryption. Which solutions will meet these requirements?
Community Votes
65% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether candidates understand that AWS KMS GenerateDataKey returns both a plaintext key (for local encryption) and an encrypted key (for safe storage), and that KMS itself should not be used to encrypt large data payloads directly.
This question tests the correct implementation of AWS KMS envelope encryption for large files. The community consensus confirms that the plaintext data key should be used locally to encrypt the file, while the encrypted data key is stored on disk for later decryption.
Many candidates choose option C, mistakenly believing that the KMS Encrypt API should be used to encrypt the file. This is incorrect because KMS is designed for encrypting small data (up to 4 KB), not large files like a 1 MB+ PDF.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding AWS KMS Envelope Encryption
This question is a classic test of envelope encryption using AWS KMS. Envelope encryption is the standard practice for protecting large amounts of data. It involves two layers: a data key (used to encrypt the actual data) and a master key (the KMS key, used to encrypt the data key).
Why Option A is Correct
When you call the GenerateDataKey API, AWS KMS returns two values: 1. Plaintext key – used immediately to encrypt your data locally (outside of KMS). 2. Encrypted key (CiphertextBlob) – the same data key, but encrypted by the KMS master key.
The correct workflow is:
- Use the plaintext key with a symmetric encryption algorithm (e.g., AES-256 via a client-side SDK) to encrypt the PDF file.
- Discard the plaintext key from memory after encryption.
- Store the encrypted key alongside the encrypted PDF on disk.
Why Options B, C, and D are Wrong
- Option B reverses the roles: it stores the plaintext key (a major security risk) and tries to use the encrypted key for encryption, which is nonsensical.
- Option C suggests using the KMS Encrypt API to encrypt the PDF. However, the KMS Encrypt API has a 4 KB payload limit. A PDF larger than 1 MB cannot be encrypted this way. Moreover, sending large data over the network to KMS is inefficient and costly.
- Option D combines both mistakes: storing the plaintext key and trying to use the encrypted key via the KMS Encrypt API.
Community Insight
As noted by community members, AWS KMS is designed for encrypting small data such as keys or short strings. For larger files, you must perform the encryption client-side using the plaintext data key. This is the essence of envelope encryption and is a heavily tested concept on the DVA-C02 exam.
Official Reference
Exam Strategy
When you see 'GenerateDataKey' and large data in a KMS question, immediately think envelope encryption: plaintext key encrypts data locally, encrypted key is stored. Eliminate any option that sends large payloads to the KMS Encrypt/Decrypt APIs.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →