CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 39: AWS Certified Security - Specialty(Old)

Which option for the use of the AWS Key Management Service (KMS) supports key management best practices that focus on minimizing the potential scope of data exposed by a possible future key compromise?

Nội dung câu hỏi

Which option for the use of the AWS Key Management Service (KMS) supports key management best practices that focus on minimizing the potential scope of data exposed by a possible future key compromise?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Use KMS automatic key rotation to replace the master key, and use this new master key for future encryption operations without re-encrypting previously encrypted data.
  2. B. Generate a new Customer Master Key (CMK), re-encrypt all existing data with the new CMK, and use it for all future encryption operations. — đáp án hiện tại
  3. C. Change the CMK alias every 90 days, and update key-calling applications with the new key alias.
  4. D. Change the CMK permissions to ensure that individuals who can provision keys are not the same individuals who can use the keys.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề