Phase Verbs / Action Phrases
| Phrase | Meaning |
|---|---|
| encrypt (a volume) | apply AES-256 encryption so data is unreadable without the key |
| enable encryption | turn on the encryption flag when creating a volume or copying a snapshot |
| copy (snapshot with encryption) | duplicating a snapshot while enabling encryption — converts unencrypted to encrypted |
| leverage (KMS keys) | use AWS Key Management Service keys for the encryption process |
| handle (encryption transparently) | EC2/EBS manages encryption/decryption without your involvement |
Technical Vocabulary
| Term | Definition |
|---|---|
| KMS (Key Management Service) | AWS service that manages cryptographic keys; used by EBS for encryption keys |
| AES-256 | Symmetric encryption standard; very strong; used for EBS data encryption |
| Data at rest | Data stored on the volume (not being transferred) |
| Data in flight | Data being read/written between EC2 instance and EBS volume |
| Encrypted snapshot | A snapshot that is encrypted; creating a volume from it produces an encrypted volume |
Key Concepts
What Gets Encrypted?
When you create an encrypted EBS volume, ALL of the following are encrypted automatically:
| What | Encrypted? |
|---|---|
| Data at rest on the volume | ✅ Yes |
| Data in-flight (EC2 ↔ EBS) | ✅ Yes |
| All snapshots of the volume | ✅ Yes |
| All volumes created from encrypted snapshots | ✅ Yes |
How EBS Encryption Works
- Uses KMS with AES-256 keys
- Encryption/decryption is transparent — you do nothing extra
- Minimal impact on latency (essentially zero performance cost)
- Keys managed by KMS; AWS handles all cryptographic operations
How to Encrypt an Existing Unencrypted EBS Volume
You cannot directly encrypt an existing unencrypted EBS volume. The process is:
- Create a snapshot of the unencrypted volume
- Copy the snapshot with encryption enabled (this creates an encrypted snapshot)
- Create a new EBS volume from the encrypted snapshot → new volume is encrypted
- Attach the encrypted volume to the instance and detach the old one
Shortcut: When creating a volume from a snapshot, you can enable encryption inline without a separate copy step.
Encryption Propagation Rules
| Source | Result |
|---|---|
| Unencrypted volume | Unencrypted snapshot |
| Unencrypted snapshot → copy with encryption | Encrypted snapshot |
| Encrypted snapshot → create volume | Encrypted volume |
| Encrypted volume → snapshot | Encrypted snapshot |
Exam Tips
- Enabling encryption = no performance penalty (minimal latency impact)
- Encryption uses KMS / AES-256 — AWS handles this transparently
- To encrypt an existing volume: snapshot → copy with encryption → new volume from snapshot
- An encrypted volume’s snapshots are automatically encrypted
- A volume created from an encrypted snapshot is automatically encrypted
- You cannot change the encryption state of an existing volume directly