KMS is AWS’s Key Management Service — it creates and controls the encryption keys that protect your data. Most AWS services integrate with it, so you can encrypt S3 objects, EBS volumes, RDS databases, and more with keys you manage and audit.
What the exam tests
Know that KMS manages encryption keys, integrates with services like S3/EBS/RDS, and logs key usage to CloudTrail for auditing. Customer-managed keys give you control over rotation and policies; AWS-managed keys are simpler. For dedicated hardware isolation, that’s CloudHSM.
Test yourself
A company must encrypt data at rest across S3 and EBS, control key rotation, and audit every use of the keys. Which service?
- AWS KMS
- AWS IAM
- Amazon Macie
- AWS Shield
👉 Click to reveal the answer & explanation
Correct answer: A. KMS creates and manages encryption keys, integrates with S3 and EBS, supports rotation policies, and logs usage to CloudTrail for auditing. IAM (B) governs permissions, not keys; Macie (C) discovers sensitive data; Shield (D) is DDoS protection.
Related topics
AWS IAM · Amazon S3 · Shared Responsibility Model
Ready to pass your AWS exam?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026