The image shows the AWS console page for an Oracle Database@AWS Exadata VM cluster (“pm-demo-exadb-vmcluster”), with the IAM service roles tab highlighted. In this section, you can associate or disassociate an IAM role used for AWS integrations, and there’s a link to CloudFormation templates to help create the required service roles. The table at the bottom lists a service role ARN whose status is Connected, and it’s associated with the AWS KMS for TDE integration. Overall, it’s confirming that the VM cluster has an IAM role wired up to use AWS KMS for database encryption key management.