GregLab | Exam Prep

Security, Identity, and Compliance

AWS Key Management Service (KMS)

AWS Key Management Service (KMS) creates and controls cryptographic keys used by AWS services and applications. Customer-managed keys give GenAI teams policy, rotation, audit, and separation-of-duties control over protected data.

Key points

  • Key policies are a primary authorization boundary alongside IAM
  • Envelope encryption lets services protect large data with data keys
  • Grants provide scoped delegated use for many service integrations

When to use it

  • Encrypt a knowledge-base S3 bucket and vector store with a controlled key
  • Separate tenant or environment cryptographic boundaries for sensitive artifacts

Exam tips

  • Choose KMS for managed keys and the Encryption SDK when application-side envelope encryption is required
  • Grant both the workload and integrating service the exact key operations; S3 permission alone is insufficient

Free AWS Certified Generative AI Developer - Professional prep

Build focused AIP-C01 quizzes from exam domains, topics, and AWS services.

Practice with exam-style multiple-choice and multiple-response questions, clearly labeled supplemental exercises, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Build a quiz

Exam Weights

Quiz builder

Choose your practice set

Mode

Exam fidelity: AWS lists multiple choice and multiple response for this exam. Ordering, matching, and case-study items are supplemental learning exercises; their results stay in overall study accuracy but do not count toward exam-style accuracy. Difficulty labels describe this site's scenario complexity, not an AWS-published question rating.

Reference

AIP-C01 topics and service map

Study links

AIP-C01 resources