Q6Data Protection
What is the effect of the following AWS Key Management Service (AWS KMS} key policy that is attached to a customer managed key?
← → navigate · a answer
Community votes
Discussion · 2
C 1
Selected Answer: C
This correctly says that the key can be used to encrypt/decrypt only when (1) the principal is ExampleRole AND (2) the request originates from WorkMail or SES in us-west-2. That is exactly what the kms:ViaService condition enforces.
C 1
Selected Answer: C
Via Service means - the service making the operation call