CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 117: AWS Certified Security - Specialty(Old)

An Amazon EC2 instance is denied access to a newly created AWS KMS CMK used for decrypt actions. The environment has the following configuration: ✑ The instance is allowed the kms:Decrypt action in its IAM role for all resources ✑ The AWS KMS CMK status is set to enabled ✑ The instance can communicate with the KMS API…

Nội dung câu hỏi

An Amazon EC2 instance is denied access to a newly created AWS KMS CMK used for decrypt actions. The environment has the following configuration: ✑ The instance is allowed the kms:Decrypt action in its IAM role for all resources ✑ The AWS KMS CMK status is set to enabled ✑ The instance can communicate with the KMS API using a configured VPC endpointWhat is causing the issue?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. The kms:GenerateDataKey permission is missing from the EC2 instance's IAM role
  2. B. The ARN tag on the CMK contains the EC2 instance's ID instead of the instance's ARN
  3. C. The kms:Encrypt permission is missing from the EC2 IAM role
  4. D. The KMS CMK key policy that enables IAM user permissions is missing — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề