[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cheat-sheet---en":3,"domain-info---en":3,"topic-info----en":3,"lesson-aws-certified-cloudops-engineer-associate-security-and-compliance-data-protection-encryption-in-transit-with-acm-en":4,"prev-aws-certified-cloudops-engineer-associate-security-and-compliance-data-protection-encryption-in-transit-with-acm-en":20,"next-aws-certified-cloudops-engineer-associate-security-and-compliance-data-protection-encryption-in-transit-with-acm-en":34},null,{"locked":5,"reason":6,"meta":7,"item":3},true,"paywall",{"title":8,"description":9,"isFree":10,"estimatedMinutes":11,"difficulty":12,"learningObjectives":13},"Encryption in Transit with ACM","How to get TLS certificates that renew themselves, why some ACM certificates quietly do not, and how to terminate and enforce TLS across load balancers, CloudFront, and S3.",false,26,"intermediate",[14,15,16,17,18,19],"Describe what ACM manages and where an ACM certificate can and cannot be used","Compare DNS, email, and HTTP domain validation and explain the renewal consequence of each","Determine whether a given certificate is eligible for ACM managed renewal","Select and interpret an ELB security policy for a TLS requirement","Enforce HTTPS end to end across a load balancer, CloudFront, and Amazon S3","Diagnose common certificate request, validation, and renewal failures",{"locked":5,"reason":6,"meta":21,"item":3},{"title":22,"description":23,"isFree":10,"estimatedMinutes":24,"difficulty":25,"learningObjectives":26},"Encryption at Rest with AWS KMS","How KMS actually protects data: envelope encryption and data keys, the 3 key types, why a key policy behaves unlike every other resource policy, rotation and what it does not do, the deletion waiting period, and the failures these produce in S3 and EBS.",32,"advanced",[27,28,29,30,31,32,33],"Explain envelope encryption and trace a GenerateDataKey call through encryption and decryption","Choose between customer managed, AWS managed, and AWS owned keys for a stated control requirement","Explain why a KMS key policy must grant access explicitly and how cross-account key access is authorized","Distinguish grants from key policies, and describe what encryption context adds","Describe what automatic key rotation changes and what it deliberately leaves alone","Apply the key deletion waiting period and key states to a recovery scenario","Diagnose common encryption failures in Amazon S3 and Amazon EBS",{"locked":5,"reason":6,"meta":35,"item":3},{"title":36,"description":37,"isFree":10,"estimatedMinutes":11,"difficulty":12,"learningObjectives":38},"Secrets Management","Where credentials belong on AWS and why: Parameter Store tiers and SecureString, Secrets Manager rotation and staging labels, cross-account access, and the failures each design produces.",[39,40,41,42,43,44],"Choose between Secrets Manager, Parameter Store, and AppConfig for a stated requirement","Apply Parameter Store's standard and advanced tier limits to a design decision","Trace a secret through the 4 rotation steps and the AWSCURRENT, AWSPENDING, and AWSPREVIOUS staging labels","Compare single user and alternating users rotation, and identify when managed rotation applies","Configure cross-account and cross-Region access to a secret, including the KMS key requirement","Diagnose common secret retrieval, rotation, and deletion failures"]