User Tools

Site Tools


aws:security:kms

This is an old revision of the document!


KMS (Key Management Service)

What it is: A service to create, manage, and control access to encryption keys.

What it’s for:

  • Encrypt data in AWS services (S3, EBS, RDS, DynamoDB, etc.).
  • Control who can use keys to encrypt/decrypt.
  • Audit key usage.

Key ideas:

Exam cues:

  • “encrypt S3 objects with customer control” → SSE-KMS + customer-managed key.
  • “control who can decrypt” → KMS + key policy.

Hard words:

  • *encryption* /ɪnˈkrɪpʃən/: mã hóa
  • *decrypt* /ˌdiːˈkrɪpt/: giải mã
  • *audit* /ˈɔːdɪt/: kiểm toán/ghi nhận
  • *regional* /ˈriːdʒənl/: theo Region
aws/security/kms.1766904402.txt.gz · Last modified: by phong2018