S3 Encryption Flashcards

1
Q

Match each of these to the definition:

______= object level keys, master key rotation

_______= use envelope to retrieve private keys, keys under customer control

______= customer managed keys given to S3 to encrypt/decrypt objects

______= encrypt/decrypt handled at client end, S3 sees only encrypted objects

______= SSL/TLS is turned on for objects by default

  1. Client Side Encryption
  2. In-Transit
  3. SSE-S3 - S3 Managed Keys
  4. SSE-C
  5. SSE-KMS
A

SSE-S3 - S3 Managed Keys = object level keys, master key rotation

SSE-KMS= use envelope to retrieve private keys, keys under customer control

SSE-CS= customer managed keys given to S3 to encrypt/decrypt objects

Client Side Encryption = encrypt/decrypt handled at client end, S3 sees only encrypted objects

In-Transit = SSL/TLS is turned on for objects by default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly