Domain 5 · Data protection
18% of the exam. Who controls the keys, how traffic stays encrypted, how stored data survives deletion and ransomware, and how secrets and sensitive fields stay out of sight.
Domain 5 questions hand you a piece of data (an object, a volume, a database password, a log line with a card number in it) and a requirement: nobody but the payments team can read it, it must survive a rogue administrator, it must be kept for seven years and then disappear, it must never cross the internet in cleartext. The right answer is usually the managed control that enforces the requirement, not code you would have to write and audit.
| Task | What it's really asking | Pages |
|---|---|---|
| 5.1 Data in transit | Forcing TLS everywhere, choosing where TLS terminates, private paths to services, encryption between cluster nodes | Encryption in transit, Hybrid and private access |
| 5.2 Data at rest | KMS vs CloudHSM, client- vs server-side, immutability, retention, backups that ransomware can't delete | KMS key management, S3 data protection, Storage encryption, Backup and ransomware protection |
| 5.3 Credentials, secrets and key material | Rotating secrets, importing or holding your own key material, masking sensitive data, keys and certificates across Regions | Key material and HSMs, Secrets management, Sensitive data |
How to read Domain 5 questions:
- "Who can decrypt?" is almost always a key policy question. Encryption that anyone with
s3:GetObjectcan undo (SSE-S3) doesn't separate duties; a customer managed KMS key does. - "Even the root user must not delete it" points to a compliance-mode lock: S3 Object Lock, AWS Backup Vault Lock, or a logically air-gapped vault. Governance mode can be bypassed by design.
- "Keys must never be in AWS" or "we must be able to cut AWS off" is an external key store. "Single-tenant HSM" is CloudHSM. Plain "FIPS 140-3 validated" is satisfied by KMS itself.
- "Least operational overhead" favours managed rotation, default encryption settings and org-wide policies over Lambda functions and scripts.
What connects Domain 5 to the rest of the exam:
- Key policies and resource policies follow the same evaluation logic as IAM. See Policy evaluation and Organization policies for SCPs and RCPs that enforce encryption across accounts.
- Private connectivity (VPC endpoints, PrivateLink, Client VPN, Verified Access) lives in Hybrid and private access.
- A leaked secret or a deleted key during an incident is handled in Compromised credentials.
Encryption is not access control
Turning on encryption with an AWS managed key changes nothing about who can read the data: anyone the service lets in gets plaintext back. When a question says a team must be unable to read data they can otherwise reach, the fix is a customer managed key whose key policy excludes them, not "enable encryption".
Least-privilege tooling and troubleshooting
IAM Access Analyzer external, internal and unused access findings, policy validation, generation and custom checks, the IAM policy simulator, last accessed data, and reading AccessDenied messages.
KMS key management
KMS key types and ownership, key policies, grants and condition keys, envelope encryption, rotation, multi-Region and cross-account keys, and safe deletion.