ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 166 - SCS-C01 discussion

Report
Export

The Security Engineer created a new AWS Key Management Service (AWS KMS) key with the following key policy:

What are the effects of the key policy? (Choose two.)

A.
The policy allows access for the AWS account 111122223333 to manage key access though IAM policies.
Answers
A.
The policy allows access for the AWS account 111122223333 to manage key access though IAM policies.
B.
The policy allows all IAM users in account 111122223333 to have full access to the KMS key.
Answers
B.
The policy allows all IAM users in account 111122223333 to have full access to the KMS key.
C.
The policy allows the root user in account 111122223333 to have full access to the KMS key.
Answers
C.
The policy allows the root user in account 111122223333 to have full access to the KMS key.
D.
The policy allows the KMS service-linked role in account 111122223333 to have full access to the KMS key.
Answers
D.
The policy allows the KMS service-linked role in account 111122223333 to have full access to the KMS key.
E.
The policy allows all IAM roles in account 111122223333 to have full access to the KMS key.
Answers
E.
The policy allows all IAM roles in account 111122223333 to have full access to the KMS key.
Suggested answer: A, C

Explanation:

Giving the AWS account full access to the CMK does this; it enables you to use IAM policies to give IAM users and roles in the account access to the CMK. It does not by itself give any IAM users or roles access to the CMK, but it enables you to use IAM policies to do so.

https://docs.aws.amazon.com/kms/latest/developerguide/key-policies.html#key-policy-defaultallow-root-enable-iam

asked 16/09/2024
Edgar Santiago
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first