AWS Certified CloudOps Engineer - Associate
Encryption at Rest with AWS KMS
How KMS actually protects data: envelope encryption and data keys, the 3 key types, why a key policy behaves unlike every other resource policy, rotation and what it does not do, the deletion waiting period, and the failures these produce in S3 and EBS.
Advanced 32 minutes 7 Learning Objectives
- Explain envelope encryption and trace a GenerateDataKey call through encryption and decryption
- Choose between customer managed, AWS managed, and AWS owned keys for a stated control requirement
- Explain why a KMS key policy must grant access explicitly and how cross-account key access is authorized
- Distinguish grants from key policies, and describe what encryption context adds
- Describe what automatic key rotation changes and what it deliberately leaves alone
- Apply the key deletion waiting period and key states to a recovery scenario
- Diagnose common encryption failures in Amazon S3 and Amazon EBS
