What it is: Two common ownership models for KMS keys.
What it’s for: Choose the right control level for encryption.
AWS-managed key:
Customer-managed key (CMK):
You create and manage key settings and policies.
More control over access, rotation, and auditing.
Exam cues:
Hard words:
*ownership* /ˈoʊnərʃɪp/: quyền sở hữu
*rotation* /roʊˈteɪʃn/: xoay vòng khóa
*control level* /kənˈtroʊl ˈlevl/: mức độ kiểm soát