A. Ensure the KMS policy allows the AppUser role to have permission to decrypt for the CMK.
B. Ensure the S3 bucket policy allows the AppUser role to have permission to get objects for the S3 bucket.
C. Ensure the CMK was created before the S3 bucket.
D. Ensure the S3 block public access feature is enabled for the S3 bucket.
E. Ensure that automatic key rotation is disabled for the CMK.
F. Ensure the SCPs within Organizations allow access to the S3 bucket.
- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.
Join the Discussion
You must be logged in to post a comment.