**KMS role**: Centralized key management. Creates and controls encryption keys. Used by S3, EBS, RDS, Lambda for encryption. **Why KMS**: Key lifecycle (creation, rotation, deletion); audit via CloudTrail; access control via IAM. **CMK**: Customer-managed keys—you control policy and rotation. AWS-managed keys are simpler but less control. **Best practice**: Use CMK for compliance (audit trail). Enable automatic rotation (annual for symmetric). **Cost**: $1/month per key; $0.03/10K requests....
The complete answer continues with detailed implementation patterns, architectural trade-offs, and production-grade considerations. It covers performance optimization strategies, common pitfalls to avoid, and real-world examples from companies like Nielsen. The answer also includes follow-up discussion points that interviewers commonly explore.
Continue Reading the Full Answer
Unlock the complete expert answer with code examples, trade-offs, and pro tips - plus 1,863+ more.
Or upgrade to Platform Pro - $39
Engineers who used these answers got offers at
AmazonDatabricksSnowflakeGoogleMeta
According to DataEngPrep.tech, this is one of the most frequently asked Cloud/Tools interview questions, reported at 1 company. DataEngPrep.tech maintains a curated database of 1,863+ real data engineering interview questions across 7 categories, verified by industry professionals.