What's changed: In-scope coverage: added identity (Cognito/Directory Service/IAM Identity Center), keys/certs (CloudHSM/ACM), threat detection (GuardDuty/Inspector/Macie/Detective/Security Hub), network defense (Network Firewall/Firewall Manager), and compliance (Artifact/Audit Manager) across sections
1.2Data Protection and Encryption
Understand data protection design: encryption at rest/in transit, key management with AWS KMS, encrypting S3/EBS/RDS, and secrets management with Secrets Manager.
Protect data both at rest and in transit. On AWS, manage keys centrally with KMS and enable each service’s encryption.
1.2.1Data protection elements
- Encryption at rest: encrypt S3, EBS, RDS, DynamoDB, etc., with KMS keys—often just a toggle.
- Encryption in transit: protect client-to-service traffic with TLS/HTTPS.
- AWS KMS: centrally create/manage keys with CloudTrail-audited usage; AWS-managed vs more controllable customer-managed keys.
- Secrets Manager: store secrets (DB creds, API keys) with automatic rotation. SSM Parameter Store stores config/secrets (with a free tier).
| Protects | Service/method | Note |
|---|---|---|
| Data at rest | KMS encryption (S3/EBS/RDS) | Key usage auditable |
| Data in transit | TLS/HTTPS | Certs via ACM |
| Encryption keys | AWS KMS | AWS- vs customer-managed |
| Secrets | Secrets Manager / Parameter Store | Auto-rotation available |
The design principle is "always encrypt, at rest and in transit." On AWS many services enable at-rest encryption by default or with one click, and KMS manages keys centrally. Keys come as AWS-managed defaults or customer-managed keys where you control policy and rotation—choose a customer-managed key for strict audit needs. Secrets (passwords, connection strings, API keys) should not be hard-coded; store them in Secrets Manager (with auto-rotation) or SSM Parameter Store, and have apps fetch them via an IAM role. TLS certificates can be issued and auto-renewed by ACM (Certificate Manager).
Scenario: a web app using RDS. Encrypt RDS and its EBS at rest with KMS (customer-managed key); encrypt app⇔RDS and user⇔ALB in transit with TLS (certs via ACM). Store DB credentials in Secrets Manager with auto-rotation, fetched by the app via an IAM role (no embedded keys). Audit key usage with CloudTrail.
Watch the mix-ups: (1) keys = KMS / secrets = Secrets Manager (or Parameter Store)—different roles. (2) Encrypt both at rest and in transit (not just one). (3) Don’t hard-code secrets—fetch via an IAM role. (4) customer-managed vs AWS-managed keys (degree of control/audit).
Q. KMS vs Secrets Manager? KMS manages encryption keys; Secrets Manager manages secrets like passwords (with auto-rotation). Q. AWS-managed vs customer-managed key? A customer-managed key lets you control key policy/rotation—fits strict audit needs. Q. Certificates? Issue/auto-renew with ACM and attach to ALB or CloudFront.
Common: key management = KMS (AWS-managed/customer-managed), secrets management/rotation = Secrets Manager, certificates = ACM, and encrypt both at rest (KMS) and in transit (TLS). Never hard-code secrets—fetch via IAM role.
1.2.2Other key in-scope services (keys and certificates)
Beyond KMS and Secrets Manager, know the options for stricter-compliance key management and certificate management. AWS CloudHSM provides dedicated hardware security modules (HSMs)—choose it when you must solely control keys and meet strict requirements such as FIPS 140-3 Level 3 (current hsm2m type) or custom key custody (versus KMS, which is multi-tenant managed keys that are simpler to operate). AWS Certificate Manager (ACM) issues and auto-renews SSL/TLS certificates—choose it to attach certificates to ELB or CloudFront and maintain encryption in transit with no operational overhead.
| What you want | Service |
|---|---|
| Dedicated HSM, sole key control | AWS CloudHSM |
| Issue/auto-renew TLS certificates | AWS Certificate Manager (ACM) |
1.2.3Section summary
- Always encrypt both at rest (KMS) and in transit (TLS/ACM)
- Use KMS (keys; AWS-managed/customer-managed) vs Secrets Manager (secrets; auto-rotation); fetch via IAM role
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which AWS service centrally creates and manages encryption keys?
Q2. Which service securely stores and auto-rotates secrets like database credentials?
Q3. Which is the best practice for protecting data?

