A company is required to use cryptographic keys in its on-premises key manager. The key manager is outside of the AWS Cloud because of regulatory and compliance requirements. The company wants to manage encryption and decryption by using cryptographic keys that are retained outside of the AWS Cloud and that support a variety of external key managers from different vendors. Which solution will meet these requirements with the LEAST operational overhead?
AUse AWS CloudHSM key store backed by a CloudHSM cluster.
BUse an AWS Key Management Service (AWS KMS) external key store backed by an external key manager.
CUse the default AWS Key Management Service (AWS KMS) managed key store.
DUse a custom key store backed by an AWS CloudHSM cluster.