I'm looking into encrypting an SQS Queue that I've got using the CDK, and as options, there are
| Encryption type | Description |
|---|---|
| UNENCRYPTED | Messages in the queue are not encrypted. |
| KMS_MANAGED | Server-side KMS encryption with a KMS key managed by SQS |
| SQS_MANAGED | Server-side encryption key managed by SQS (SSE-SQS) |
| KMS | Server-side encryption with a KMS key managed by the user. |
but I don't understand the significance in the difference between #2 and #3. Both KMS_MANAGED and SQS_MANAGED have a Service Side encrypted key that's managed by SQS, but in the former case that is a KMS key, and in the latter case there is no KMS key.
Now... why does that matter to me as an end user / person who's looking to encrypt? In both cases, AWS is managing the key, what difference does it make to me whether they use key A or key B to do it, when in both cases I don't have control, and both cases are assumably secure?
Essentially, I don't understand the significance of it being a KMS managed key or not, when in both cases, it is encrypted safely?