ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 393 - SOA-C02 discussion

Report
Export

The SysOps administrator needs to create a key policy that grants data engineers least privilege access to decrypt and read data from an S3 bucket encrypted with KMS.

A.

'kms:ReEncrypt*', 'kms:GenerateDataKey*', 'kms:Encrypt', 'kms:DescribeKey'

Answers
A.

'kms:ReEncrypt*', 'kms:GenerateDataKey*', 'kms:Encrypt', 'kms:DescribeKey'

B.

'kms:ListAliases', 'kms:GetKeyPolicy', 'kms:Describe*', 'kms:Decrypt'

Answers
B.

'kms:ListAliases', 'kms:GetKeyPolicy', 'kms:Describe*', 'kms:Decrypt'

C.

'kms:ListAliases', 'kms:DescribeKey', 'kms:Decrypt'

Answers
C.

'kms:ListAliases', 'kms:DescribeKey', 'kms:Decrypt'

D.

'kms:Update*', 'kms:TagResource', 'kms:Revoke*', 'kms:Put*', 'kms:List*', 'kms:Get*', 'kms:Enable*', 'kms:Disable*', 'kms:Describe*', 'kms:Delete*', 'kms:Create*', kms:CancelKeyDeletion

Answers
D.

'kms:Update*', 'kms:TagResource', 'kms:Revoke*', 'kms:Put*', 'kms:List*', 'kms:Get*', 'kms:Enable*', 'kms:Disable*', 'kms:Describe*', 'kms:Delete*', 'kms:Create*', kms:CancelKeyDeletion

Suggested answer: C

Explanation:

The least privilege required for reading encrypted data involves kms:Decrypt to decrypt, kms:DescribeKey to understand key properties, and kms:ListAliases if needed to identify the key alias.

asked 06/11/2024
Antonios Petropoulos
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first