List of questions
Related questions
Question 407 - SOA-C02 discussion
The SysOps administrator needs to complete the KMS key policy for least privilege read access for the DataEngineer role to decrypt S3 objects encrypted with a KMS key.
A.
'kms:ReEncrypt', 'kms:GenerateDataKey*', 'kms:Encrypt', 'kms:DescribeKey'
B.
'kms:ListAliases', 'kms:GetKeyPolicy', 'kms:Describe*', 'kms:Decrypt'
C.
'kms:ListAliases', 'kms:DescribeKey', 'kms:Decrypt'
D.
'kms:Update*', 'kms:TagResource', 'kms:Revoke*', 'kms:Put*', 'kms:List*', 'kms:Get*', 'kms:Enable*', 'kms:Disable*', 'kms:Describe*', 'kms:Delete*', 'kms:Create*', 'kms:CancelKeyDeletion'
Your answer:
0 comments
Sorted by
Leave a comment first