
Explore the AWS key management service (KMS) concepts in this introduction, designed to simplify KMS and support certification prep for associate, professional, and security exams for cloud and security engineers.
Learn key management service terminologies, including data at rest and in transit, encryption and decryption, plaintext and ciphertext, symmetric and asymmetric keys, HSMs, CMKs, data keys, envelope encryption, and alias.
Explore how AWS KMS uses hardware security modules to manage customer master keys and data keys, enabling envelope encryption, generating and importing key material, and service integration.
https://aws.amazon.com/kms/pricing/
Discover how to create a customer master key in the AWS KMS console, set an alias and description, generate a key policy, and assign a key admin and key user.
IAM policy Evaluation Logic:
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html
IAM policy Evaluation Logic:
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html
IAM policy Evaluation Logic:
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html
Learn to create a customer master key (CMK) in AWS KMS with default KMS generated key material, assign admins and users, and understand key policy, aliases, and tags.
Importing Key Material Reference:https://docs.aws.amazon.com/kms/latest/developerguide/importing-keys-encrypt-key-material.html
CLI Documentation Page with install links:
https://aws.amazon.com/cli/
Configure AWS CLI profiles for users a, b, and c using their access keys, then test permissions by listing S3 buckets and preparing to encrypt and decrypt with KMS keys.
IAM policy Evaluation Logic:
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html
Encrypt S3 data with a KMS customer master key or the S3 master key, applying at bucket or object level and choosing region-specific, account-specific keys.
S3 CLI Reference:
I have added this access control Lab in this section because we have to know few commands for this lab which we covered in this section.
AWS GRANTS LAB:
Learn to encrypt an EBS volume using your KMS customer master key by enabling encryption during volume creation and selecting the desired key.
Enable automatic rotation for customer master keys with generated material to renew backing key yearly, while preserving the key ID and aliases, and schedule deletion with a 7-30 day wait.
Learners practice enabling and disabling a customer master key in AWS KMS, noting that a disabled CMK cannot encrypt or decrypt data, and that S3 keys can't be disabled.
Schedule deletion of a customer master key in AWS KMS within seven to thirty days, noting the pending deletion state and that data cannot be decrypted.
This course provides a complete hands on introduction to AWS Key Management Service(KMS). We have a fast paced style of delivery. The lectures and labs/demo are planned and edited to pack the most content in shortest time. This is a must take course to pass the AWS Security exam. Taught by an instructor who has successfully passed the AWS Security Speciality Exam.
This course includes Labs/demo using the Management Console and the command line interface(CLI).
What the students are saying:
"The pace is good, the presenter peaks very clearly, and the information is presented in a very straightforward way - it is clear they thought a lot about how to present the information in the most clear and concise way."
"Very clear Awesome Pace"
"I really enjoyed the course. I picked up a thing or 2. I think the topic was covered well."
"Great explanation on basic fundamentals"
We will cover topics including:
- Customer Master Key creation with Imported Key Materials
- Generating and using data keys
- Using CMK to import data
- Key Rotation
- Key Access controls
- AWS Managed vs Customer Managed Keys
- Key Lifecycle Management
Why take this course?
1) KMS is integral to encryption of data on AWS.
2) KMS is featured in several AWS Exams and heavily featured in the AWS Security exam.
3) To get an good understanding of KMS so you can identify the best solutions which KMS provides and fits your need.
4) You will get all the future updates we have on the course.
5) Get free Course Slides that you can use for study
6) 30 day money- back guarantee. If you aren't satisfied, we will happily refund you.
7) The instructor is 12x AWS Certified including the AWS Security speciality cert where KMS is heavily featured.