Understanding how to manage encryption keys and implement encryption is key to the Security – Specialty certification and, in particular, AWS Key Management Service plays a big part. Data protection is always on people's minds when storing data within the cloud, and so the different approaches to encryption and the different mechanisms available are important topics to understand. Having a good understanding of how to encrypt data in AWS will allow you to confidently build secure solutions for you and your customers.
As a result, it's important that we cover KMS and that you are familiar with its workings and how it can be used by other AWS services to protect your data. Within this chapter, I will be covering AWS Key Management Service, known as KMS, in addition to an overview of AWS CloudHSM, which is another service used to manage...