Q: 5
A security team manages a company’s AWS Key Management Service (AWS KMS) customer managed
keys. Only members of the security team can administer the KMS keys. The company's application
team has a software process that needs temporary access to the keys occasionally. The security team
needs to provide the application team's software process with access to the keys.
Which solution will meet these requirements with the LEAST operational overhead?
Options
Discussion
This looks like one from my exam last year. in some practice sets. Option C
C or B-I'm thinking C for lower effort since grants can be created and revoked quickly without fiddling with the policy each time. Policy changes are riskier and more work. Anyone see a catch with grants here?
B
Be respectful. No spam.