A. In the statement block that contains the Sid ג€Allow use of the keyג€, under the ג€Conditionג€ block, change StringEquals to StringLike.
B. In the policy document, remove the statement block that contains the Sid ג€Enable IAM User Permissionsג€. Add key management policies to the KMS policy.
C. In the statement block that contains the Sid ג€Allow use of the keyג€, under the ג€Conditionג€ block, change the kms:ViaService value to ec2.us-east- 1.amazonaws.com.
D. In the policy document, add a new statement block that grants the kms:Disable* permission to the security engineer’s IAM role.
- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.
Join the Discussion
You must be logged in to post a comment.