AWS Security & Encryption: KMS, SSM Parameter Store, Cloud HSM, Shield & WAF Flashcards
What is Encryption in flight (SSL)?
What is Server side encryption at rest?
What is Client side encryption?
What is AWS KMS (Key Management Service)?
What are the different types of KMS Keys Types available?
What are the different types of KMS Keys?
How does automation key rotation work in AWS KMS?
How would you copy encrypted EBS snapshots across regions?
What are KMS Key Policies?
How are KMS Key Policies used in the process of copying encrypted snapshots across accounts?
What are KMS Multi-Region Keys?
Why would you use KMS Multi-Region Keys?
How does DynamoDB Global Tables and KMS MultiRegion Keys Client-Side encryption work?
How does Global Aurora and KMS Multi-Region Keys Client-Side encryption work?
What are some S3 Replication
Encryption Considerations?
Should you use Multi-Region KMS Keys with S3 replication?
You can use multi-region AWS KMS Keys, but they are currently treated as independent keys by Amazon S3 (the object will still be decrypted and then encrypted).
How do you share an AMI when the AMI is encrypted via a KMS key?
How do you share an AMI across accounts?
You modify the Launch Permission in the origin account and add the specified target account