Infrastructure Security Flashcards

1
Q

You are setting up guarduty to write encrypted data to s3 what three permission types do you need to add ?

A

1 - S3 policy - to allow Guardduty to use the bucket
2 - Key Policy - to allow Guardduty to use the CMK
3 - Addition to the key policy to allow Guardduty to generate a data key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a key policy in KMS ?

A

A reource based policy that controls access to the CMK

How well did you know this?
1
Not at all
2
3
4
5
Perfectly