This screenshot shows Step 1: Configure key in the AWS KMS Create key wizard. The selections indicate a symmetric key intended to encrypt and decrypt data. In Advanced options, the key material origin is set to KMS (AWS-managed key material creation) and the key is configured as a single-Region key (not replicated to other regions). The Next button will proceed to adding labels and setting permissions/policy.