The image shows an “Encryption” settings section where key management is set to an AWS Customer Managed Key. It indicates the specific KMS key being used via the alias alias/pm-demo-awskmskey. On the right, a Rotate button (highlighted in red) is available to rotate that customer-managed encryption key, which is a common best practice for key lifecycle management.