KMS Flashcards
KMS means
Key management service
What type of cryptography does KMS use?
Symmetric.
What does KMS do?
Stores and generates encrypted keys used by other services
Can AWS staff access your KMS keys?
Nope.
KMS is for encryption at rest only. True or false?
True
Is KMS region specific?
Yes
Components of KMS
CMK
DEK
Key Policies
Grant
What does DEK mean?
Data encryption key
What does CMK mean?
Customer Master Key
CMK encryption size limit
4kb
Two types of of CMK are
Customer managed
AWS managed
In KMS. All CMKs require a Key Policy. True or false?
True
What are the three methods for accessing a CMK?
Key policy
IAM policy
Grants
KMS automatic key rotation, changes the keys on what timeline?
Once a year.
This can not be modified.
A KMS CMK key is breached. Would rotating the key fix the issue?
Nope!