ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 220 - SCS-C01 discussion

Report
Export

An Amazon S3 bucket is encrypted using an AWS KMS CMK. An IAM user is unable to download objects from the S3 bucket using the AWS Management Console; however, other users can download objects from the S3 bucket. Which policies should the Security Engineer review and modify to resolve this issue? (Select three.)

A.
The CMK policy
Answers
A.
The CMK policy
B.
The VPC endpoint policy
Answers
B.
The VPC endpoint policy
C.
The S3 bucket policy
Answers
C.
The S3 bucket policy
D.
The S3 ACL
Answers
D.
The S3 ACL
E.
The IAM policy
Answers
E.
The IAM policy
Suggested answer: A, C, E

Explanation:

https://aws.amazon.com/premiumsupport/knowledge-center/decrypt-kms-encrypted-objects-s3/

asked 16/09/2024
Vladimir Litvinenko
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first