Ends in
00
days
00
hrs
00
mins
00
secs
SHOP NOW

💝 Valentine's Sale! Get 30% OFF Any Reviewer. Use coupon code: VDAYSALE2026 & 5% OFF Store Credits/Gift Cards

Find answers, ask questions, and connect with our
community around the world.

Home Forums AWS AWS Certified Security – Specialty Envelope Encryption – Ambiguous answer

  • Envelope Encryption – Ambiguous answer

  • Ocean

    Member
    September 17, 2025 at 7:08 am

    A company is developing an online customer portal in AWS. There is a requirement to create and control the encryption keys used to encrypt your data using the envelope encryption strategy to comply with the strict IT security policy of the company.

    Which of the following statements correctly describes the envelope encryption process?

    I believe the highlighted answer in the attached screenshot is ambiguous and not accurate as

    ” top-level master key is never exposed as plaintext; only the data key is used as plaintext during data encryption, and its encrypted form is stored alongside the ciphertext for secure key management and retrieval.”

    or in simple words

    “It is a process where you encrypt plaintext data with a data key, and then encrypt that data key with a top-level key encryption key (KEK).”

    please clarify!!

    Thanks

  • Irene-TutorialsDojo

    Administrator
    September 19, 2025 at 1:16 pm

    Hi Ocean,

    Thank you for your feedback. You are correct that the description could be clearer. In envelope encryption, the data key is used to encrypt plaintext data, and then the data key itself is encrypted using a top-level Key Encryption Key (KEK). The KEK is never exposed as plaintext, ensuring secure key management and retrieval. We will update the relevant information to reflect this clarification and ensure it aligns with the accurate process.

    Thank you for bringing this to our attention!

    If you have further questions or need additional clarification, please don’t hesitate to contact us.

    Best,

    Irene @ Tutorials Dojo

Viewing 1 - 2 of 2 replies

Log in to reply.

Original Post
0 of 0 posts June 2018
Now
Skip to content