Solved

A Security Engineer Is Looking for a Way to Control

Question 135

Multiple Choice

A Security Engineer is looking for a way to control access to data that is being encrypted under a CMK. The Engineer is also looking to use additional authenticated data (AAD) to prevent tampering with ciphertext. Which action would provide the required functionality?


A) Pass the key alias to AWS KMS when calling Encrypt and Decrypt API actions. Pass the key alias to AWS KMS when calling Encrypt and Decrypt API actions.
B) Use IAM policies to restrict access to Encrypt and Decrypt API actions. Use IAM policies to restrict access to
C) Use kms:EncryptionContext as a condition when defining IAM policies for the CMK. Use kms:EncryptionContext as a condition when defining IAM policies for the CMK.
D) Use key policies to restrict access to the appropriate IAM groups.

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions

Unlock this Answer For Free Now!

View this answer and more for free by performing one of the following actions

qr-code

Scan the QR code to install the App and get 2 free unlocks

upload documents

Unlock quizzes for free by uploading documents