Case 15ACEC · Cloud · L2 Practitioner
Envelope Encryption with KMS
Practise as: Explain it · Interview
Interview questionWhat is envelope encryption and why do cloud KMS services use it?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Data is encrypted with a data key; the data key is encrypted by a master key that never leaves the KMS/HSM
- Scales: bulk crypto happens locally, only small data keys go to KMS, avoiding size and rate limits
- Access control moves to the key policy: no kms:Decrypt permission means no plaintext even with the ciphertext
- Rotating the master key does not require re-encrypting bulk data; at most the small data keys are rewrapped
- Customer-managed keys add control (own key policy, rotation, disable/delete) at the cost of availability risk
If the interviewer pushes back
- If someone can read an encrypted S3 object, what else must they have to see plaintext?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.