Ends in
00
days
00
hrs
00
mins
00
secs
SHOP NOW

🚀 43% OFF AZ-104 & AWS CloudOps Reviewers

Find answers, ask questions, and connect with our
community around the world.

Home Forums AWS AWS Certified Security – Specialty Potentially incorrect answer Reply To: Potentially incorrect answer

  • JR-TutorialsDojo

    Administrator
    July 16, 2026 at 8:51 pm

    Hello achie27,

    Thank you for sharing your thoughts on this item.

    You’re correct that KMS now holds FIPS 140-3 Level 3 validation and supports VPC endpoints. The deciding requirement is key custody. KMS keys live in AWS’s multi-tenant HSM fleet, so you control usage through key policies but not the key material itself. CloudHSM clusters are single-tenant, meaning you own the HSM users and credentials, and AWS has no path to your keys at all.

    On “AWS should only manage the HSM appliance,” that phrasing actually points toward CloudHSM rather than away from it. That is exactly the CloudHSM split: AWS provisions, patches, and maintains the hardware, while you manage the users, keys, and crypto operations.

    Thanks for flagging this. We’ll be refining the rationale for the incorrect options to make the distinction clearer, and the update should appear on the portal soon.

    I hope this helps! Let us know if you need further assistance.

    Regards,
    JR @ Tutorials Dojo

Skip to content