Chapter 9, Managing Secrets

  1. False  the KMS service allows you to use AWS-created keys as well as your own private keys
  2. A KMS alias
  3. CloudFormation Exports
  4. False  you can recover the secret for a configurable period of time, up to a maximum of 30 days
  5. The AWS CLI and jq utility
  6. You must grant the kms:Decrypt permission for the KMS key that was used to encrypt the secret value
  1. The NoEcho property
  2. The AWS_DEFAULT_REGION environment variable