AWS Certified Security - Specialty: 9 Sample questions

From wikieduonline
Revision as of 12:25, 24 November 2021 by Welcome (talk | contribs)
Jump to navigation Jump to search

1) A corporate cloud security policy states that communication between the company's VPC and KMS

must travel entirely within the AWS network and not use public service endpoints.
Which combination of the following actions MOST satisfies this requirement? (Select TWO.)
A) Add the aws:sourceVpce condition to the AWS KMS key policy referencing the company's VPC
endpoint ID.
B) Remove the VPC internet gateway from the VPC and add a virtual private gateway to the VPC to prevent
direct, public internet connectivity.
C) Create a VPC endpoint for AWS KMS with private DNS enabled.
D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN.
E) Add the following condition to the AWS KMS key policy: "aws:SourceIp": "10.0.0.0/16"

Advertising: