AWS Service for Managing Encryption Keys
Which AWS service can a company use to manage encryption keys in the cloud?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between certificate management (ACM) and cryptographic key management (CloudHSM), with the trap being confusion between certificates and keys.
AWS CloudHSM is the correct service for managing encryption keys in the cloud, providing dedicated hardware security modules. This page establishes why CloudHSM is preferred over ACM for raw key management.
Learners often select AWS Certificate Manager (ACM), confusing digital certificates with the underlying encryption keys they utilize.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS CloudHSM (Hardware Security Module) is designed specifically to help you generate and manage your own encryption keys securely in the AWS Cloud. It provides dedicated HSM instances that allow you to control the lifecycle of your keys, ensuring they remain under your exclusive control. This aligns perfectly with the requirement to "manage encryption keys" as opposed to managing higher-level abstractions like certificates.Why the Other Options Are Wrong
AWS License Manager is used for tracking software licenses across on-premises and virtual environments, not for cryptography. AWS Certificate Manager (ACM) simplifies the deployment of SSL/TLS certificates for AWS services but does not give you direct access to manage the underlying private keys; ACM manages the certificates, while CloudHSM manages the keys. AWS Directory Service provides managed Microsoft Active Directory in the cloud, which is unrelated to encryption key generation or storage.Community Comment Notes
Community consensus strongly supports CloudHSM, with users noting it enables generating and storing encryption keys on a dedicated hardware appliance. One commenter highlighted the keyword distinction: "encryption keys" points to CloudHSM, whereas "certificates" would point to ACM. Another user confirmed that CloudHSM allows secure generation and storage of cryptographic keys accessible only to the customer.Official Reference
Exam Strategy
When asked about 'managing encryption keys' directly, think of HSMs (KMS or CloudHSM). If the question specifies 'SSL/TLS certificates' or 'deploying HTTPS', choose ACM. Distinguish between the tool that holds the key (HSM/KMS) and the tool that uses it for web traffic (ACM).
Frequently Asked Questions
Why is ACM wrong if it handles SSL keys?
ACM manages certificates, not the raw encryption keys themselves. You cannot export or directly manage the private keys in ACM.
What is the difference between KMS and CloudHSM here?
Both manage keys, but CloudHSM provides dedicated hardware appliances. The question's context often favors CloudHSM when emphasizing 'hardware' or 'dedicated' management.
Related Analysis
Practice All CLF-C02 Questions
Access 120 questions with complete answers and detailed explanations.
View Full CLF-C02 Practice Test →