The city uses AWS Key Management Service (AWS KMS) for encryption. Who is responsible for key policy and encryption configuration choices that protect municipal data?
Select an answer to reveal the explanation.
Short Explanation
AWS builds the lock factory; the city still chooses which locks go on which doors and who holds the keys. KMS is the service; key policies and encryption settings for municipal data are customer choices. Providing the tool does not make AWS the author of your data-protection decisions.
Full Explanation
Customers are responsible for protecting their data, including encryption configuration and key policy choices when using AWS KMS. AWS provides the KMS service and underlying infrastructure, but does not unilaterally set every customer key policy for municipal workloads. CloudFront does not own all KMS policies, and encryption decisions remain part of customer data-protection responsibility.