A corporate cloud security policy states that communications between the company's VPC and KMS must travel entirely within the AWS network and not use public service endpoints. Which combination of the following actions MOST satisfies this requirement? (Choose two.)
A) Add the aws:sourceVpce condition to the AWS KMS key policy referencing the company's VPC endpoint ID. Add the aws:sourceVpce condition to the AWS KMS key policy referencing the company's VPC endpoint ID.
B) Remove the VPC internet gateway from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity.
C) Create a VPC endpoint for AWS KMS with private DNS enabled.
D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN.
E) Add the following condition to the AWS KMS key policy: "aws:SourceIp": "10.0.0.0/16". Add the following condition to the AWS KMS key policy: "aws:SourceIp": "10.0.0.0/16".
Correct Answer:
Verified
Q123: A Security Engineer has discovered that, although
Q124: A Security Engineer is setting up an
Q125: A company has enabled Amazon GuardDuty in
Q126: An organization receives an alert that indicates
Q127: A Security Administrator at a university is
Q129: The Security team believes that a former
Q130: An organization is using Amazon CloudWatch Logs
Q131: What are the MOST secure ways to
Q132: The Security Engineer for a mobile game
Q133: A Security Engineer discovered a vulnerability in
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents