How to Encrypt a Large PDF File Using AWS KMS GenerateDataKey?

A developer is writing an application that will retrieve sensitive data from a third-party system. The application will format the data into a PDF file. The PDF file could be more than 1 MB. The application will encrypt the data to disk by using AWS Key Management Service (AWS KMS). The application will decrypt the file when a user requests to download it. The retrieval and formatting portions of the application are complete. The developer needs to use the GenerateDataKey API to encrypt the PDF file so that the PDF file can be decrypted later. The developer needs to use an AWS KMS symmetric customer managed key for encryption. Which solutions will meet these requirements?

  1. Write the encrypted key from the GenerateDataKey API to disk for later use. Use the plaintext key from the GenerateDataKey API and a symmetric encryption algorithm to encrypt the file. Source Reference Answer
  2. Write the plain text key from the GenerateDataKey API to disk for later use. Use the encrypted key from the GenerateDataKey API and a symmetric encryption algorithm to encrypt the file.
  3. Write the encrypted key from the GenerateDataKey API to disk for later use. Use the plaintext key from the GenerateDataKey API to encrypt the file by using the KMS Encrypt API.
  4. Write the plain text key from the GenerateDataKey API to disk for later use. Use the encrypted key from the GenerateDataKey API to encrypt the file by using the KMS Encrypt API.

Community Votes

A
65%
C
35%

65% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether candidates understand that AWS KMS GenerateDataKey returns both a plaintext key (for local encryption) and an encrypted key (for safe storage), and that KMS itself should not be used to encrypt large data payloads directly.

This question tests the correct implementation of AWS KMS envelope encryption for large files. The community consensus confirms that the plaintext data key should be used locally to encrypt the file, while the encrypted data key is stored on disk for later decryption.

Many candidates choose option C, mistakenly believing that the KMS Encrypt API should be used to encrypt the file. This is incorrect because KMS is designed for encrypting small data (up to 4 KB), not large files like a 1 MB+ PDF.

Community Discussion (11 comments)

CrescentShared 👍 6 Selected: A
Using the KMS Encrypt API to encrypt large amounts of data, such as a PDF file that could be more than 1 MB, is not efficient and can be costly. AWS KMS is designed for encrypting small amounts of data, such as encryption keys or short strings. For larger data, it's recommended to use a client-side encryption library with a data key generated by KMS.
0bdf3af 👍 1 Selected: C
C. We use KMS Encrypt API and this method is called envelope encyrption. KMS will generate plaintext key which we have to store on the disk. We use it to encrypt file by calling KMS API
preachr 👍 1 Selected: A
To encrypt data outside of AWS KMS: 1) Use the GenerateDataKey operation to get a data key. 2) Use the plaintext data key (in the Plaintext field of the response) to encrypt your data outside of AWS KMS. Then erase the plaintext data key from memory. 3) Store the encrypted data key (in the CiphertextBlob field of the response) with the encrypted data.
wh1t4k3r 👍 1 Selected: C
Where is the KMS key element on A?
jyrajan69 👍 2
The question clearly says using KMS so why would you even consider A and B
65703c1 👍 2 Selected: A
A is the correct answer.
DeaconStJohn 👍 1 Selected: C
Going with my gut.
SerialiDr 👍 2 Selected: A
Option A is the most appropriate method for encrypting a PDF file using AWS KMS, where the plaintext key is used for encryption operations, and the encrypted key (not the plaintext key) is stored or managed externally for later decryption use.
Abdullah22 👍 1
going with C
KarBiswa 👍 3 Selected: C
https://docs.aws.amazon.com/kms/latest/APIReference/API_GenerateDataKey.html
ANDRES715 👍 1 Selected: D
Según la documentación de AWS, cuando se utiliza la API GenerateDataKey, se obtiene una clave de texto sin formato y una clave cifrada. La clave de texto sin formato se puede escribir en el disco para su uso posterior, mientras que la clave cifrada se utiliza para cifrar los datos. En este caso, el desarrollador debe escribir la clave de texto sin formato en el disco para su uso posterior y utilizar la clave cifrada para cifrar el archivo PDF mediante la API de cifrado KMS.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding AWS KMS Envelope Encryption

This question is a classic test of envelope encryption using AWS KMS. Envelope encryption is the standard practice for protecting large amounts of data. It involves two layers: a data key (used to encrypt the actual data) and a master key (the KMS key, used to encrypt the data key).

Why Option A is Correct

When you call the GenerateDataKey API, AWS KMS returns two values: 1. Plaintext key – used immediately to encrypt your data locally (outside of KMS). 2. Encrypted key (CiphertextBlob) – the same data key, but encrypted by the KMS master key.

The correct workflow is:

  • Use the plaintext key with a symmetric encryption algorithm (e.g., AES-256 via a client-side SDK) to encrypt the PDF file.
  • Discard the plaintext key from memory after encryption.
  • Store the encrypted key alongside the encrypted PDF on disk.
When the user requests the file later, you send the encrypted key to KMS via Decrypt, get the plaintext key back, and use it to decrypt the PDF.

Why Options B, C, and D are Wrong

  • Option B reverses the roles: it stores the plaintext key (a major security risk) and tries to use the encrypted key for encryption, which is nonsensical.
  • Option C suggests using the KMS Encrypt API to encrypt the PDF. However, the KMS Encrypt API has a 4 KB payload limit. A PDF larger than 1 MB cannot be encrypted this way. Moreover, sending large data over the network to KMS is inefficient and costly.
  • Option D combines both mistakes: storing the plaintext key and trying to use the encrypted key via the KMS Encrypt API.

Community Insight

As noted by community members, AWS KMS is designed for encrypting small data such as keys or short strings. For larger files, you must perform the encryption client-side using the plaintext data key. This is the essence of envelope encryption and is a heavily tested concept on the DVA-C02 exam.

Official Reference

Exam Strategy

When you see 'GenerateDataKey' and large data in a KMS question, immediately think envelope encryption: plaintext key encrypts data locally, encrypted key is stored. Eliminate any option that sends large payloads to the KMS Encrypt/Decrypt APIs.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide