StudyToCert

All certifications / Cloud Practitioner / Lessons

AWS Certified Cloud Practitioner CLF-C02 · Domain 2: Security and Compliance

Encryption at rest and in transit: AWS KMS, AWS CloudHSM and AWS Certificate Manager

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Encryption protects data so that only someone with the right key can read it. You need it in two places. Encryption at rest protects stored data, such as objects in Amazon Simple Storage Service (Amazon S3), volumes in Amazon Elastic Block Store (Amazon EBS) or rows in a database. Encryption in transit protects data moving across a network, usually with Transport Layer Security (TLS), which is what HTTPS uses. The Cloud Practitioner exam asks you to choose among three services that support these: AWS Key Management Service, AWS CloudHSM and AWS Certificate Manager.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Cloud Practitioner for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Cloud Practitioner study plan