Difference between revisions of "AWS Certified Security - Specialty: 9 Sample questions"

From wikieduonline
Jump to navigation Jump to search
Line 5: Line 5:
 
:D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN.
 
:D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN.
 
:E) Add the following condition to the AWS KMS key policy: <code>"aws:SourceIp": "10.0.0.0/16"</code>
 
:E) Add the following condition to the AWS KMS key policy: <code>"aws:SourceIp": "10.0.0.0/16"</code>
 +
 +
 +
 +
== See also ==
 +
* [[AWS Certified Security - Specialty]]

Revision as of 12:41, 24 November 2021

1) A corporate cloud security policy states that communication between the company's VPC and KMS must travel entirely within the AWS network and not use public service endpoints. Which combination of the following actions MOST satisfies this requirement? (Select TWO.)

A) Add the aws:sourceVpce condition to the AWS KMS key policy referencing the company's VPC endpoint ID.
B) Remove the VPC internet gateway from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity.
C) Create a VPC endpoint for AWS KMS with private DNS enabled.
D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN.
E) Add the following condition to the AWS KMS key policy: "aws:SourceIp": "10.0.0.0/16"


See also

Advertising: