Solved

An Amazon EC2 Instance Is Denied Access to a Newly

Question 94

Multiple Choice

An Amazon EC2 instance is denied access to a newly created AWS KMS CMK used for decrypt actions. The environment has the following configuration: The instance is allowed the kms:Decrypt action in its IAM role for all resources The AWS KMS CMK status is set to enabled The instance can communicate with the KMS API using a configured VPC endpoint What is causing the issue?


A) The kms:GenerateDataKey permission is missing from the EC2 instance's IAM role
B) The ARN tag on the CMK contains the EC2 instance's ID instead of the instance's ARN
C) The kms:Encrypt permission is missing from the EC2 IAM role
D) The KMS CMK key policy that enables IAM user permissions is missing

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions

Unlock this Answer For Free Now!

View this answer and more for free by performing one of the following actions

qr-code

Scan the QR code to install the App and get 2 free unlocks

upload documents

Unlock quizzes for free by uploading documents