AWS SAA – Lecture 65: EBS Encryption

Published on
Written by Henry Nguyen

Phase Verbs / Action Phrases

PhraseMeaning
encrypt (a volume)apply AES-256 encryption so data is unreadable without the key
enable encryptionturn on the encryption flag when creating a volume or copying a snapshot
copy (snapshot with encryption)duplicating a snapshot while enabling encryption — converts unencrypted to encrypted
leverage (KMS keys)use AWS Key Management Service keys for the encryption process
handle (encryption transparently)EC2/EBS manages encryption/decryption without your involvement

Technical Vocabulary

TermDefinition
KMS (Key Management Service)AWS service that manages cryptographic keys; used by EBS for encryption keys
AES-256Symmetric encryption standard; very strong; used for EBS data encryption
Data at restData stored on the volume (not being transferred)
Data in flightData being read/written between EC2 instance and EBS volume
Encrypted snapshotA snapshot that is encrypted; creating a volume from it produces an encrypted volume

Key Concepts

What Gets Encrypted?

When you create an encrypted EBS volume, ALL of the following are encrypted automatically:

WhatEncrypted?
Data at rest on the volume✅ Yes
Data in-flight (EC2 ↔ EBS)✅ Yes
All snapshots of the volume✅ Yes
All volumes created from encrypted snapshots✅ Yes

How EBS Encryption Works

  • Uses KMS with AES-256 keys
  • Encryption/decryption is transparent — you do nothing extra
  • Minimal impact on latency (essentially zero performance cost)
  • Keys managed by KMS; AWS handles all cryptographic operations

How to Encrypt an Existing Unencrypted EBS Volume

You cannot directly encrypt an existing unencrypted EBS volume. The process is:

  1. Create a snapshot of the unencrypted volume
  2. Copy the snapshot with encryption enabled (this creates an encrypted snapshot)
  3. Create a new EBS volume from the encrypted snapshot → new volume is encrypted
  4. Attach the encrypted volume to the instance and detach the old one

Shortcut: When creating a volume from a snapshot, you can enable encryption inline without a separate copy step.

Encryption Propagation Rules

SourceResult
Unencrypted volumeUnencrypted snapshot
Unencrypted snapshot → copy with encryptionEncrypted snapshot
Encrypted snapshot → create volumeEncrypted volume
Encrypted volume → snapshotEncrypted snapshot

Exam Tips

  • Enabling encryption = no performance penalty (minimal latency impact)
  • Encryption uses KMS / AES-256 — AWS handles this transparently
  • To encrypt an existing volume: snapshot → copy with encryption → new volume from snapshot
  • An encrypted volume’s snapshots are automatically encrypted
  • A volume created from an encrypted snapshot is automatically encrypted
  • You cannot change the encryption state of an existing volume directly