Protect data in transit
Select and troubleshoot TLS, certificate, private-path, service-to-service, and inter-resource encryption controls.
- Lesson
- d5-lesson
- Practice pool
- d5-questions
- Application
- scs-l06
Protect data in transit, at rest, and in use through ownership-aware encryption, key lifecycle decisions, secret handling, discovery, masking, and evidence.
Select and troubleshoot TLS, certificate, private-path, service-to-service, and inter-resource encryption controls.
Choose encryption ownership, key material, rotation, grants, multi-Region strategy, access evidence, and recovery behavior.
Discover, classify, mask, store, rotate, scope, and monitor access to confidential material throughout its lifecycle.
Classify the information, identify owners and custodians, and trace collection, use, sharing, retention, recovery, and deletion. Then choose protection for data in transit, at rest, and where relevant in use. Encryption does not fix overbroad access, poor retention, or exposed plaintext in logs.
Map every hop: client to edge, edge to origin, service to service, node to node, hybrid path, and administrative channel. Choose certificates, trust roots, TLS policies, mutual authentication, private paths, and inter-resource encryption from threat and compliance requirements. Validate the negotiated path and failure behavior rather than relying on a configuration label.
Distinguish AWS-owned, AWS-managed, and customer-managed keys. Customer-managed KMS keys add policy, grant, rotation, usage-evidence, deletion, and cross-account responsibilities. Imported material shifts lifecycle and recoverability duties. Multi-Region keys are for designs that need compatible key material across Regions; they do not replicate encrypted data or remove application failover work.
Use managed secret storage, workload identities, rotation, scoped access, version stages, failure alarms, and audit evidence. Discover and mask sensitive data where appropriate. Never emit secrets, raw credentials, or protected prompts into logs.
For one cross-account, multi-Region data flow, defend the key owner, policies, certificate path, rotation behavior, recovery plan, and evidence that proves authorized and denied use.