Home › Forums › AWS › AWS Certified Security – Specialty › Envelope Encryption – Ambiguous answer › Reply To: Envelope Encryption – Ambiguous answer
-
Hi Ocean,
Thank you for your feedback. You are correct that the description could be clearer. In envelope encryption, the data key is used to encrypt plaintext data, and then the data key itself is encrypted using a top-level Key Encryption Key (KEK). The KEK is never exposed as plaintext, ensuring secure key management and retrieval. We will update the relevant information to reflect this clarification and ensure it aligns with the accurate process.
Thank you for bringing this to our attention!
If you have further questions or need additional clarification, please don’t hesitate to contact us.
Best,
Irene @ Tutorials Dojo