exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 310 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 310
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A security engineer needs to create an AWS Key Management Service (AWS KMS) key that will be used to encrypt all data stored in a company's Amazon S3 buckets in the us-west-1 Region. The key will use server-side encryption. Usage of the key must be limited to requests coming from Amazon S3 within the company's account.
Which statement in the KMS key policy will meet these requirements?
A.

B.

C.

D.

Show Suggested Answer Hide Answer
Suggested Answer: D

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sam_live
Highly Voted 2 years, 11 months ago
A correct answer. https://docs.aws.amazon.com/kms/latest/developerguide/policy-conditions.html#conditions-kms-caller-account
upvoted 16 times
Tofu13
1 year, 7 months ago
updated link https://docs.aws.amazon.com/kms/latest/developerguide/conditions-kms.html#conditions-kms-caller-account
upvoted 2 times
...
...
Raphaello
Most Recent 10 months, 1 week ago
Correct answer is A. kms:ViaService kms:CallerAccount Will do the job!
upvoted 1 times
...
Raphaello
10 months, 1 week ago
A. A is the correct answer.
upvoted 1 times
...
c73bf38
1 year, 9 months ago
A:The policy grants permission to the AWS account root user to perform encryption, decryption, re-encryption, generate data keys, and describe the key operations on all KMS keys. The policy includes a condition that restricts access to requests coming from the same account and requests with an S3 source ARN that matches the account ID and us-west-1 Region.
upvoted 1 times
...
maddyr
2 years ago
Agree with A
upvoted 1 times
...
D2
2 years ago
Answer A
upvoted 1 times
...
AdamWest
2 years, 1 month ago
A Is correct
upvoted 3 times
...
roger8978
2 years, 11 months ago
A .....
upvoted 1 times
...
sam_live
2 years, 11 months ago
A is correct. Any resources & condition via service s3.us-west-1.amazonaws.com.
upvoted 1 times
...
argol
2 years, 11 months ago
"A" is the answer
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago