Security, Identity, and Compliance
CoreAWS KMS
Explicit encryption-at-rest configuration and troubleshooting.
Key points
- KMS key use can depend on IAM, key policy, grants, key state and Region, service integration, and encryption context.
Best-known use cases
- D4.1, D4.2, and D5.1: enable or troubleshoot the named at-rest encryption and decryption path.
What candidates often confuse it with
- KMS manages encryption keys; ACM manages TLS certificates and Secrets Manager manages secret values and rotation.
Key takeaway
Resource access does not imply key use, so evaluate data permission and KMS authorization separately.
Related services
- AWS Certificate Manager (ACM)
- Amazon EC2 security groups
- Egress-only internet gateways
Relevant exam tasks
- D4.1 — Task 4.1: Implement and manage security and compliance tools and policies.
- 4.1.1 — Implement IAM features (for example, password policies, multi-factor authentication [MFA], roles, federated identity, resource policies, policy conditions).
- D4.2 — Task 4.2: Implement strategies to protect data and infrastructure.
- 4.2.1 — Implement and enforce a data classification scheme.
- D5.1 — Task 5.1: Implement and optimize networking features and connectivity.
- 5.1.1 — Configure a VPC (for example, subnets, route tables, network ACLs, security groups, NAT gateways, internet gateway, egress-only internet gateway).