ETExamTower
Q6Data Protection

What is the effect of the following AWS Key Management Service (AWS KMS} key policy that is attached to a customer managed key?

Question exhibit
← → navigate · a answer
Community votes
C
100% (3)
A
0% (0)
B
0% (0)
D
0% (0)
Discussion · 2
C 1
Selected Answer: C This correctly says that the key can be used to encrypt/decrypt only when (1) the principal is ExampleRole AND (2) the request originates from WorkMail or SES in us-west-2. That is exactly what the kms:ViaService condition enforces.
C 1
Selected Answer: C Via Service means - the service making the operation call