Encrypt training data, logs, and backups.
Separate administrators by purpose.
Choose two designs.
Separate KMS keys by purpose, environment, or account, and audit usage, rotation, deletion waiting periods, and cross-account grants.
Detailed explanation
One key compromise has a smaller scope.
One key compromise has a smaller scope.
The key lifecycle is controlled.
The key lifecycle is controlled.
Mistakes and compromise spread.
Mistakes and compromise spread.
Deletion and retention requirements differ.
Deletion and retention requirements differ.
Try it yourself
An example you can run in a temporary verification environment.
AWS KMS公式とAIF-C01 Domain 5.1の暗号化、キーポリシー、鍵管理を確認する。Expected result
AIデータの暗号鍵を用途別に管理し、鍵操作を監査できる。Key points
- KMS
- Key separation
- Rotation
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.