AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A retail company wants to encrypt sensitive customer data stored in Amazon S3 and maintain full control over the lifecycle and rotation of the encryption keys, including the ability to disable or delete keys. Which service should they use to manage these keys?
- AAWS Secrets Manager
- BAmazon Macie
- CAWS Certificate Manager
- DAWS Key Management Service (KMS)
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Key Management Service (KMS)
AWS KMS allows customers to create, manage, rotate, and control access to encryption keys used to protect data across AWS services such as S3, including the ability to disable or schedule deletion of keys.
Why the other options are wrong
- A. Secrets Manager stores and rotates secrets like database credentials, not general encryption keys.
- B. Macie discovers and classifies sensitive data but does not manage encryption keys.
- C. Certificate Manager issues and manages SSL/TLS certificates, not general-purpose encryption keys.
AWS Key Management Service (KMS)
A managed service for creating and controlling encryption keys used to encrypt data across AWS services.
- Supports automatic annual key rotation for customer-managed keys
- Integrates with S3, EBS, RDS, and other services for encryption
- Customers can define key policies and control who can use or manage keys
Memory trick: KMS is the master keyring for all your encryption keys.