AWS Service

AWS Key Management Service

KMS creates and controls cryptographic keys used by AWS services and applications.

What This Service Solves

KMS creates and controls cryptographic keys used by AWS services and applications.

  • Use KMS for managed key control, envelope encryption, key policies, grants, and auditability.

When You Should Not Use It

  • Do not assume KMS authorization replaces IAM or application authorization. It controls key use.

What AWS Manages and What You Manage

AWS protects key material for AWS managed keys and KMS keys. You manage key policies, grants, rotation choices, aliases, and access review.

Security Implications

Key policy plus IAM must allow use. Explicit denies, grants, and cross-account use are common exam details.

Availability and Scaling

KMS keys are regional unless multi-Region keys are chosen. If a service cannot use the key, encrypted data may become unavailable.

Request quotas matter for high-throughput encryption workflows.

Cost Behavior

Customer managed keys, requests, and multi-Region keys can add cost.

Common Integrations

  • S3
  • EBS
  • RDS
  • DynamoDB
  • Lambda
  • CloudTrail

How AWS Might Present It

Certification-Specific Depth

AIF-C01

AI Practitioner

Know what the service does and when it is the right family.

DVA-C02

Developer Associate

Know configuration choices, integrations, failure modes, security, operations, and cost tradeoffs.

DEA-C01

Data Engineer Associate

Know configuration choices, integrations, failure modes, security, operations, and cost tradeoffs.

Sources and Review Metadata

This independent training application is not affiliated with or endorsed by Amazon Web Services. AWS, Amazon Web Services, and AWS certification names are trademarks of Amazon.com, Inc. or its affiliates.