Which AWS service can a company use to manage cryptographic keys in the cloud?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS CloudHSM.
Why this is the answer
AWS CloudHSM is the correct answer because it provides hardware security modules (HSMs) in the AWS cloud, allowing you to generate and manage your own encryption keys using FIPS 140-2 Level 3 validated HSMs. This service is designed for applications requiring strong cryptographic key management and regulatory compliance. AWS License Manager helps manage software licenses from vendors like Microsoft and Oracle, not cryptographic keys. AWS Certificate Manager (ACM) provisions, manages, and deploys SSL/TLS certificates for use with AWS services, but it doesn't manage general-purpose cryptographic keys for applications. AWS Directory Service allows you to set up and run directories in the AWS Cloud or connect your AWS resources with an existing on-premises Microsoft Active Directory, which is for identity and access management, not cryptographic key management.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed