CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 78: AWS Certified Security - Specialty(Old)

A Development team has asked for help configuring the IAM roles and policies in a new AWS account. The team using the account expects to have hundreds of master keys and therefore does not want to manage access control for customer master keys (CMKs). Which of the following will allow the team to manage AWS KMS permis…

Nội dung câu hỏi

A Development team has asked for help configuring the IAM roles and policies in a new AWS account. The team using the account expects to have hundreds of master keys and therefore does not want to manage access control for customer master keys (CMKs). Which of the following will allow the team to manage AWS KMS permissions in IAM without the complexity of editing individual key policies?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. The account's CMK key policy must allow the account's IAM roles to perform KMS EnableKey.
  2. B. Newly created CMKs must have a key policy that allows the root principal to perform all actions. — đáp án hiện tại
  3. C. Newly created CMKs must allow the root principal to perform the kms CreateGrant API operation.
  4. D. Newly created CMKs must mirror the IAM policy of the KMS key administrator.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề