AWS Key Management Service (KMS) creates and controls the keys used to encrypt data at rest across AWS services such as S3, EBS, RDS, DynamoDB and Secrets Manager. KMS key material never leaves the service unencrypted; KMS performs cryptographic operations inside validated hardware security modules (HSMs), and every use of a key is recorded in AWS CloudTrail. The exam expects you to know which kind of key to choose, how access to keys is controlled, and which S3 encryption option fits a requirement.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.