- Home
- All questions
- Question 138
AWS Certified Solutions Architect study material · question 138 of 500
Which two statements about AWS managed KMS keys are correct? Choose two.
Show the answer
Answer: C. They exist in the customer's account but work only within their own service
D. Their lifecycle and permissions cannot be edited by the account
AWS managed keys are service-scoped and unmanageable by the customer, are free to hold, and cannot protect data shared across accounts.
Source: AWS KMS keys (Amazon Web Services) — AWS KMS keys