Editing AWS Certified Security - Specialty: 9 Sample questions
Jump to navigation
Jump to search
Warning: You are not logged in. Your IP address will be publicly visible if you make any edits. If you log in or create an account, your edits will be attributed to your username, along with other benefits.
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 1: | Line 1: | ||
− | + | 1) A corporate cloud security policy states that communication between the company's VPC and KMS | |
− | + | must travel entirely within the AWS network and not use public service endpoints. | |
− | 1) A corporate cloud security policy states that | + | Which combination of the following actions MOST satisfies this requirement? (Select TWO.) |
− | + | A) Add the aws:sourceVpce condition to the AWS KMS key policy referencing the company's VPC | |
− | + | endpoint ID. | |
− | + | B) Remove the VPC internet gateway from the VPC and add a virtual private gateway to the VPC to prevent | |
− | + | direct, public internet connectivity. | |
− | + | C) Create a VPC endpoint for AWS KMS with private DNS enabled. | |
− | + | D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN. | |
− | + | E) Add the following condition to the AWS KMS key policy: "aws:SourceIp": "10.0.0.0/16" | |
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− |
Advertising: