An application running on Amazon EC2 instances must access objects within an Amazon S3 bucket that are encrypted using server-side encryption using AWS KMS encryption keys (SSE-KMS) . The application must have access to the customer master key (CMK) to decrypt the objects. Which combination of steps will grant the application access? (Choose two.)
A) Write an S3 bucket policy that grants the bucket access to the key.
B) Grant access to the key in the IAM EC2 role attached to the application's EC2 instances.
C) Write a key policy that enables IAM policies to grant access to the key.
D) Grant access to the key in the S3 bucket's ACL
E) Create a Systems Manager parameter that exposes the KMS key to the EC2 instances.
Correct Answer:
Verified
Q49: A company needs a fully-managed source control
Q50: A company needs a new REST API
Q51: A Developer is writing an imaging micro
Q52: What does an Amazon SQS delay queue
Q53: A Developer has developed a web application
Q55: An application is expected to process many
Q56: A stock market monitoring application uses Amazon
Q57: A Developer wants to encrypt new objects
Q58: A Developer is writing a serverless application
Q59: A Developer is creating a Lambda function
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents