Home > Glossary > AWS Certified Cloud Practitioner > AWS Key Management Service (KMS)

📖 What is AWS Key Management Service (KMS)?

AWS Key Management Service (KMS) is a managed service that facilitates the creation and control of cryptographic keys used for encrypting data. It supports symmetric and asymmetric encryption, allowing you to generate, store, and manage keys used with other AWS services and your applications.

🥋 Sensei Says:

"A critical exam topic. Understand the difference between AWS managed keys (automatic rotation, simpler) and customer managed keys (full control, custom rotation policies). Know how KMS integrates with services like S3, EBS, and RDS for encryption at rest. Distinguish KMS from CloudHSM."

📚 Certification: AWS Certified Cloud Practitioner (CLF-C02)

🔑 What are the Key Concepts of AWS Key Management Service (KMS)?

  • KMS customer managed keys (CMKs) offer granular control over key policies, rotation schedules, and usage, unlike AWS managed keys.
  • KMS integrates with numerous AWS services like S3, EBS, RDS, and Lambda to enable encryption at rest and in transit.
  • Key policies define permissions for who can use a CMK, controlling access based on AWS accounts, IAM users, and roles.
  • KMS supports both symmetric (single key for encryption/decryption) and asymmetric (key pair: public/private) encryption.
  • Key rotation is a security best practice; KMS automatically rotates AWS managed keys, while CMKs can be configured for custom rotation.

🎯 How does AWS Key Management Service (KMS) appear on the CLF-C02 Exam?

You may be asked to identify the AWS service best suited for centrally managing encryption keys used across multiple AWS accounts and regions.

A scenario might describe a requirement to encrypt EBS volumes at rest – determine which KMS feature or integration would fulfill this need.

Expect questions about choosing between AWS managed keys and customer managed keys based on compliance requirements and control needs.

❓ Frequently Asked Questions

When would I choose a customer managed key over an AWS managed key?

Choose CMKs when you need full control over the key lifecycle, including rotation policies, key material import, and detailed access control through key policies, often for compliance reasons.


What is the difference between KMS and CloudHSM?

KMS is a managed service where AWS manages the key material and hardware. CloudHSM allows you to control the HSM hardware and import your own keys, offering greater isolation but more operational overhead.


Can I use KMS keys to encrypt data outside of AWS?

While KMS primarily encrypts data within AWS, you can use the KMS API to encrypt data locally and then send the encrypted data to AWS. However, decryption must occur within AWS.

Related Terms from AWS Certified Cloud Practitioner

📝 Related Study Guides

Study Guide 8 min read

AWS Cloud Practitioner (CLF-C02): Complete 2026 Study Guide

The AWS Cloud Practitioner CLF-C02 certification validates foundational cloud knowledge across four domains: Cloud Concepts, Security and Compliance, Cloud Technology and Services, and Billing and Pricing. Prepare with a 4-week study plan focusing on core AWS services like EC2, S3, IAM, and Lambda, combined with scenario-based practice questions to build exam confidence.

Study Guide 10 min read

AWS Cloud Practitioner (CLF-C02) Study Guide for 2026

The AWS Cloud Practitioner (CLF-C02) exam validates overall understanding of the AWS Cloud platform. To pass, you must master four domains: Cloud Concepts, Security and Compliance, Technology, and Billing and Pricing. A successful strategy combines official AWS documentation with rigorous practice exams to benchmark your knowledge across all service categories.

Deep Dive 8 min read

AWS Support Plans & Pricing: CLF-C02 Exam Guide

AWS offers four support plans—Basic, Developer, Business, and Enterprise—differing by response time, access to engineers, and the inclusion of a Technical Account Manager (TAM). For the CLF-C02 exam, you must distinguish these tiers and understand pricing models like On-Demand, Reserved, Spot, and Savings Plans to optimize cloud costs.

🧠

Test Your Knowledge

Think you understand AWS Key Management Service (KMS)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium