From the course: AWS Certified Security - Specialty (SCS-C03) Cert Prep
Unlock this course with a free trial
Join today to access over 25,600 courses taught by industry experts.
Data and Application Protection Exam Cram - Amazon Web Services (AWS) Tutorial
From the course: AWS Certified Security - Specialty (SCS-C03) Cert Prep
Data and Application Protection Exam Cram
Welcome to the Data and Application Protection exam cram. You can create and manage symmetric and asymmetric encryption keys with KMS, and they're protected by Hardware Security Modules, HSMs. KMS keys used to be known as Customer Master Keys, or CMKs, and that terminology could still be used in various places, including the exam. KMS keys can only encrypt data up to four kilobytes in size. For anything larger, you need to create data encryption keys. AWS-managed KMS keys are created, managed, and used on your behalf by an AWS service that's integrated with KMS. You can't manage these keys, rotate them, or change their key policies. Automatic rotation of KMS keys generates new key material every year. It's optional for customer-managed keys and supported for symmetric keys with key material that AWS KMS creates. You can't use automatic rotation in the following situations. If you're using asymmetric KMS keys, you have KMS keys in custom key stores like CloudHSM, or you're using KMS…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
-
-
-
(Locked)
Section 8 - Introduction1m
-
(Locked)
Encryption at Rest and in-Transit3m 45s
-
(Locked)
AWS Certificate Manager (ACM)3m 57s
-
(Locked)
[HOL] SSL/TLS Certificate in ACM7m 10s
-
(Locked)
AWS Key Management Service (KMS)10m 38s
-
(Locked)
[HOL] Create Custom KMS Keys6m 21s
-
(Locked)
AWS CloudHSM3m 37s
-
(Locked)
Protecting Data on S3, EBS, and EFS8m 42s
-
(Locked)
[HOL] Enforce KMS Encryption for S3 Bucket4m 15s
-
(Locked)
[HOL] Copy Encrypted Snapshot Across Accounts8m 42s
-
(Locked)
Database Protection - DynamoDB and RDS5m 32s
-
(Locked)
[HOL] Encryption Options for AWS Databases7m 55s
-
(Locked)
[HOL] Schedule Key Deletion2m 23s
-
(Locked)
Storing Secrets4m 12s
-
(Locked)
Security for Lambda Functions2m 27s
-
(Locked)
AWS Step Functions2m 33s
-
(Locked)
AWS Data Lifecycle Management Features6m 42s
-
(Locked)
AWS Data Integrity Features7m 21s
-
(Locked)
[HOL] Amazon Verified Permissions4m 34s
-
(Locked)
Data and Application Protection Exam Cram7m 48s
-
(Locked)
-
-
-