The image shows a “Change key management” screen where the database’s encryption key management is set to AWS Customer Managed Key. A warning indicates there may be a brief period of database unavailability while the key management configuration is updated. The highlighted field shows the selected AWS KMS key alias (alias/pm-demo-awskmskey) and a compartment selector, with a Save changes button to apply the update. It also notes prerequisites: only AWS keys authorized for the VM cluster and registered with OCI can be selected.