Home › Forums › AWS › AWS Certified Security – Specialty › Potentially incorrect answer › Reply To: Potentially incorrect answer
-
Hello achie27,
Thank you for sharing your thoughts on this item.
You’re correct that KMS now holds FIPS 140-3 Level 3 validation and supports VPC endpoints. The deciding requirement is key custody. KMS keys live in AWS’s multi-tenant HSM fleet, so you control usage through key policies but not the key material itself. CloudHSM clusters are single-tenant, meaning you own the HSM users and credentials, and AWS has no path to your keys at all.
On “AWS should only manage the HSM appliance,” that phrasing actually points toward CloudHSM rather than away from it. That is exactly the CloudHSM split: AWS provisions, patches, and maintains the hardware, while you manage the users, keys, and crypto operations.
Thanks for flagging this. We’ll be refining the rationale for the incorrect options to make the distinction clearer, and the update should appear on the portal soon.
I hope this helps! Let us know if you need further assistance.
Regards,
JR @ Tutorials Dojo