ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 365 - SCS-C01 discussion

Report
Export

A company has been using the AW5 KMS service for managing its keys. They are planning on carrying out housekeeping activities and deleting keys which are no longer in use. What are the ways that can be incorporated to see which keys are in use? Choose 2 answers from the options given below Please select:

A.
Determine the age of the master key
Answers
A.
Determine the age of the master key
B.
See who is assigned permissions to the master key
Answers
B.
See who is assigned permissions to the master key
C.
See Cloudtrail for usage of the key
Answers
C.
See Cloudtrail for usage of the key
D.
Use AWS cloudwatch events for events generated for the key
Answers
D.
Use AWS cloudwatch events for events generated for the key
Suggested answer: B, C

Explanation:

The direct ways that can be used to see how the key is being used is to see the current access permissions and cloudtrail logs Option A is invalid because seeing how long ago the key was created would not determine the usage of the key Option D is invalid because Cloudtrail Event is better for seeing for events generated by the key This is also mentioned in the AWS Documentation Examining CMK Permissions to Determine the Scope of Potential Usage Determining who or what currently has access to a customer master key (CMK) might help you determine how widely the CM was used and whether it is still needed. To learn how to determine who or what currently has access to a CMK, go to Determining Access to an AWS KMS Customer Master Key.

Examining AWS CloudTrail Logs to Determine Actual Usage

AWS KMS is integrated with AWS CloudTrail, so all AWS KMS API activity is recorded in CloudTrail log files. If you have CloudTrail turned on in the region where your customer master key (CMK) is located, you can examine your CloudTrail log files to view a history of all AWS KMS API activity for a particular CMK, and thus its usage history. You might be able to use a CMK's usage history to help you determine whether or not you still need it For more information on determining the usage of CMK keys, please visit the following URL:

https://docs.aws.amazon.com/kms/latest/developerguide/deleting-keys-determining-usage.htmlThe correct answers are: See who is assigned permissions to the master key. See Cloudtrail for usageof the key Submit your Feedback/Queries to our Experts

asked 16/09/2024
Steven Bertoldi
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first