List of questions
Related questions
Question 429 - SCS-C01 discussion
A company has multiple Amazon S3 buckets encrypted with customer-managed CMKs Due to regulatory requirements the keys must be rotated every year. The company's Security Engineer has enabled automatic key rotation for the CMKs; however the company wants to verity that the rotation has occurred.
What should the Security Engineer do to accomplish this?
A.
Filter AWS CloudTrail logs for KeyRotaton events
B.
Monitor Amazon CloudWatcn Events for any AWS KMS CMK rotation events
C.
Using the AWS CLI. run the aws kms gel-key-relation-status operation with the --key-id parameter to check the CMK rotation date
D.
Use Amazon Athena to query AWS CloudTrail logs saved in an S3 bucket to filter Generate New Key events
Your answer:
0 comments
Sorted by
Leave a comment first