exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 37 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 37
Topic #: 1
[All AWS Certified Security - Specialty Questions]

What is the function of the following AWS Key Management Service (KMS) key policy attached to a customer master key (CMK)?

  • A. The Amazon WorkMail and Amazon SES services have delegated KMS encrypt and decrypt permissions to the ExampleUser principal in the 111122223333 account.
  • B. The ExampleUser principal can transparently encrypt and decrypt email exchanges specifically between ExampleUser and AWS.
  • C. The CMK is to be used for encrypting and decrypting only when the principal is ExampleUser and the request comes from WorkMail or SES in the specified region.
  • D. The key policy allows WorkMail or SES to encrypt or decrypt on behalf of the user for any CMK in the account.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Daniel76
Highly Voted 3 years, 6 months ago
The questions indicated that KMS key policy is attached to a specific CMK. All A, B does not mention CMK while D mention its for any CMK. C correctly states that the policy is for the CMK which policy attached to. https://docs.aws.amazon.com/kms/latest/developerguide/key-policies.html
upvoted 16 times
...
sanjaym
Highly Voted 3 years, 6 months ago
Ans: C 100%
upvoted 5 times
...
CC_AK
Most Recent 1 year, 7 months ago
D When you use the kms:ViaService condition key, the service makes the request on behalf of a principal in the AWS account.
upvoted 1 times
CC_AK
1 year, 7 months ago
https://docs.aws.amazon.com/kms/latest/developerguide/conditions-kms.html#conditions-kms-via-service
upvoted 1 times
...
...
matrpro
1 year, 12 months ago
Selected Answer: D
D is correct. The "behalf" word is the key point here: https://docs.aws.amazon.com/kms/latest/developerguide/conditions-kms.html#conditions-kms-via-service
upvoted 1 times
...
janvandermerwer
2 years, 5 months ago
Selected Answer: C
C - appears to be the right answer and makes the most sense.
upvoted 1 times
...
YouYouYou
3 years, 3 months ago
Selected Answer: C
https://www.exam4training.com/wp-content/uploads/2020/12/image020-47.jpg link for the broken img answer is C
upvoted 4 times
...
refuz
3 years, 5 months ago
Ans: C
upvoted 4 times
...
Ale_Ik
3 years, 6 months ago
C makes sense for me as well
upvoted 3 times
...
Bad_Mat
3 years, 7 months ago
C makes sense
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago