SEARCH
You are in browse mode. You must login to use MEMORY

   Log in to start


From course:

AWS Solution Architect

» Start this Course
(Practice similar questions for free)
Question:

A solutions architect needs to implement a client-side encryption mechanism for objects that will be stored in a new Amazon S3 bucket. The solutions architect created a CMK that is stored in AWS Key Management Service (AWS KMS) for this purpose.The solutions architect created the following IAM policy and attached it to an IAM role: Which action must the solutions architect add to the IAM policy to meet all the requirements? kms:GenerateDataKey kms:GetKeyPolicy kms:GetPublicKey kms:Sign

Author: Jorge Soroce



Answer:

Kms:GenerateDataKey


0 / 5  (0 ratings)

1 answer(s) in total