Encrypted, and still wrong
You have taken over a stalled security review covering three resources: two S3 buckets and one DynamoDB table. The console overview reports all three as encrypted, and a previous reviewer signed them off on that line alone.
Open the Encryption audit board. Start on Console summary to see what that reviewer saw, then switch to Full evidence and read each resource's encryption settings, key policy, and access path.
Encrypted is three answers, not one: which mode, who controls the key, and whether transit is required. Apply all three to each resource.
All three resources report as encrypted.
Which one is genuinely exposed?
This exercise is part of the course
Using AWS Security for Developers
Hands-on interactive exercise
Turn theory into action with one of our interactive exercises
Start Exercise