AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy

A company wants to encrypt data stored on an Amazon EBS volume attached to an EC2 instance without manually managing the underlying cryptographic keys. Which AWS service integrates directly with EBS to provide this encryption at rest?

  1. AAWS Secrets Manager
  2. BAWS Key Management Service (KMS)
  3. CAWS Artifact
  4. DAWS Certificate Manager
Show answer & explanation

Correct answer: B. AWS Key Management Service (KMS)

Amazon EBS encryption integrates natively with AWS KMS, using KMS keys to encrypt volumes, snapshots, and data in transit between the instance and the volume. ACM issues TLS certificates, Secrets Manager stores credentials, and Artifact provides compliance documentation—none of which encrypt EBS volumes.

Why the other options are wrong

  • A. Secrets Manager stores and rotates secrets like database credentials.
  • C. Artifact provides compliance reports, not encryption services.
  • D. ACM issues SSL/TLS certificates, not volume encryption keys.

EBS Encryption with KMS

Amazon EBS uses AWS KMS keys to encrypt volumes, snapshots, and associated data transfer, without requiring customers to manage keys manually.

  • Uses AES-256 encryption under the hood
  • Can enable account-level default encryption for all new volumes
  • Encrypted snapshots and volumes remain encrypted when copied or restored

Memory trick: KMS holds the keys that lock every EBS volume.

More Security and Compliance questions