AWS KMS
AWS Key Management Service — creates and controls encryption keys used to protect data.
AWS Key Management Service (KMS) is a managed service that creates, stores, and controls the cryptographic keys used to encrypt and decrypt data across AWS. It integrates natively with services such as S3, EBS, RDS, and Lambda, letting teams enforce encryption at rest without running key infrastructure themselves. Internally it uses FIPS-validated hardware security modules (HSMs) behind a managed API. The key exam distinction is between KMS and CloudHSM: KMS is multi-tenant and AWS-managed, the default for most workloads, while CloudHSM gives a dedicated, single-tenant HSM for regulatory needs demanding customer-exclusive hardware. Customer managed keys control rotation and access policies.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →