advanced~2h

ACM, STS & CloudHSM

Three security services that round out the AWS security toolkit: ACM for managed TLS certificates, STS for temporary credential vending, and CloudHSM for dedicated, single-tenant hardware security modules.

2
Subtopics

🎓 Learning objectives

  • Explain how ACM removes manual TLS certificate renewal for supported AWS services
  • Trace what an STS AssumeRole call actually returns and why it's temporary
  • Explain what CloudHSM offers that KMS doesn't, and why that matters for certain compliance requirements
  • Choose correctly between KMS and CloudHSM for a given key-management requirement

ACM, STS & CloudHSM is a Pro topic

Sign in, then upgrade to Pro or Power to unlock this topic and the full AWS curriculum.

📂 Subtopics

Related concepts

kms-encryptioniam-fundamentalswaf-shieldcloudfront-cdn