Certified Security - Specialty

Sign Up Free or Log In to participate!

Now KMS support Multi-Region Keys

Now KMS support Multi-Region Keys. But "Using KMS With EBS" session exam tips says we can’t copy KMS keys to another region. Could you please check and clarify? Thank you

1 Answers

You can only create multi-Region primary key as customer manage key. After creating multi-region customer manage key can be replicated to selected regions. But AWS manage keys cannot be copied or replicated to other regions yet.
https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.html

Piotr Wolnowski

The note – customer manage keys created with multi-region reginality option cannot be used to encrypt EBS volumes!

Sign In
Welcome Back!

Psst…this one if you’ve been moved to ACG!

Get Started
Who’s going to be learning?