The three explicit requirements are centralized key management, encryption in transit, and encryption at rest.
KMS satisfies centralized cryptographic-key management. It provides secure key creation, storage, lifecycle management, access control, and integration with Alibaba Cloud services such as databases and storage. Customer-managed software or hardware-protected keys can also be used where stricter compliance controls are required.
Certificate Management Service provides SSL/TLS certificates that establish encrypted HTTPS/TLS communication and verify server identity. TLS prevents sensitive transaction information from being transmitted as readable plaintext across network connections.
Transparent Data Encryption protects database data at rest. Alibaba Cloud RDS documentation identifies TDE as an encryption layer protecting database data files and backups without requiring applications to perform the underlying encryption themselves. RDS also separately supports SSL for database connection encryption.
Security Groups are an important network-access control, but the question requires exactly three controls specifically addressing encryption and centralized key management. Redis session management is unrelated.
The resulting security architecture therefore uses KMS for keys, TLS certificates for data in transit, and RDS TDE for persistent data at rest.
Study Guide reference: Securing Workloads on Alibaba Cloud — KMS, TLS/SSL, RDS encryption, TDE, and cryptographic key governance.
==================================================