Asterrr's Handbook

Domain 5 · Data protection

18% of the exam. Who controls the keys, how traffic stays encrypted, how stored data survives deletion and ransomware, and how secrets and sensitive fields stay out of sight.

Domain 5 questions hand you a piece of data (an object, a volume, a database password, a log line with a card number in it) and a requirement: nobody but the payments team can read it, it must survive a rogue administrator, it must be kept for seven years and then disappear, it must never cross the internet in cleartext. The right answer is usually the managed control that enforces the requirement, not code you would have to write and audit.

TaskWhat it's really askingPages
5.1 Data in transitForcing TLS everywhere, choosing where TLS terminates, private paths to services, encryption between cluster nodesEncryption in transit, Hybrid and private access
5.2 Data at restKMS vs CloudHSM, client- vs server-side, immutability, retention, backups that ransomware can't deleteKMS key management, S3 data protection, Storage encryption, Backup and ransomware protection
5.3 Credentials, secrets and key materialRotating secrets, importing or holding your own key material, masking sensitive data, keys and certificates across RegionsKey material and HSMs, Secrets management, Sensitive data

How to read Domain 5 questions:

  • "Who can decrypt?" is almost always a key policy question. Encryption that anyone with s3:GetObject can undo (SSE-S3) doesn't separate duties; a customer managed KMS key does.
  • "Even the root user must not delete it" points to a compliance-mode lock: S3 Object Lock, AWS Backup Vault Lock, or a logically air-gapped vault. Governance mode can be bypassed by design.
  • "Keys must never be in AWS" or "we must be able to cut AWS off" is an external key store. "Single-tenant HSM" is CloudHSM. Plain "FIPS 140-3 validated" is satisfied by KMS itself.
  • "Least operational overhead" favours managed rotation, default encryption settings and org-wide policies over Lambda functions and scripts.

What connects Domain 5 to the rest of the exam:

Encryption is not access control

Turning on encryption with an AWS managed key changes nothing about who can read the data: anyone the service lets in gets plaintext back. When a question says a team must be unable to read data they can otherwise reach, the fix is a customer managed key whose key policy excludes them, not "enable encryption".