Question:
A solutions architect needs to implement a client-side encryption mechanism for objects that will be stored in a new Amazon S3 bucket. The solutions architect created a CMK that is stored in AWS Key Management Service (AWS KMS) for this purpose.The solutions architect created the following IAM policy and attached it to an IAM role: Which action must the solutions architect add to the IAM policy to meet all the requirements? kms:GenerateDataKey kms:GetKeyPolicy kms:GetPublicKey kms:Sign
Author: Jorge SoroceAnswer:
Kms:GenerateDataKey
0 / 5 Â (0 ratings)
1 answer(s) in total