{"id":133,"date":"2021-01-04T08:10:17","date_gmt":"2021-01-04T08:10:17","guid":{"rendered":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/aws-certified-security-specialty-scs-c01-question126\/"},"modified":"2021-01-04T08:10:17","modified_gmt":"2021-01-04T08:10:17","slug":"aws-certified-security-specialty-scs-c01-question126","status":"publish","type":"post","link":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/aws-certified-security-specialty-scs-c01-question126\/","title":{"rendered":"AWS Certified Security &#8211; Specialty SCS-C01 &#8211; Question126"},"content":{"rendered":"<div class=\"question\">A corporate cloud security policy states that communications between the company&#039;s VPC and KMS must travel entirely within the AWS network and not use public service endpoints. Which combination of the following actions MOST satisfies this requirement? (Choose two.) <br \/><strong><br \/>A.<\/strong> Add the aws:sourceVpcecondition to the AWS KMS key policy referencing the company&#039;s VPC endpoint ID. <br \/><strong>B.<\/strong> Remove the VPC internet gateway from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity. <br \/><strong>C.<\/strong> Create a VPC endpoint for AWS KMS with private DNS enabled. <br \/><strong>D.<\/strong> Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN. <br \/><strong>E.<\/strong> Add the following condition to the AWS KMS key policy: &quot;aws:SourceIp&quot;: &quot;10.0.0.0\/16&quot;.<\/div>\n<p><\/p>\n<style> .hidden-div{ display:none } <\/style>\n<p>\t\t\t\t\t\t\t<button onclick=\"getElementById('hidden-div').style.display = 'block'\"> Show Answer <\/button> <button onclick=\"getElementById('hidden-div').style.display = 'none'\">Hide Answer<\/button><\/p>\n<div class=\"hidden-div\" id=\"hidden-div\"><span style=\"\"><\/p>\n<div class=\"answer\">Correct Answer: <strong>AC<\/strong><\/div>\n<p><strong>Explanation:<\/strong> <\/p>\n<div class=\"explanation\">\nExplanation An IAM policy can deny access to KMS except through your VPC endpoint with the following condition statement:<br \/>\n&#8220;Condition&#8221;: {<br \/>\n&#8220;StringNotEquals&#8221;: {<br \/>\n&#8220;aws:sourceVpce&#8221;: &#8220;vpce-0295a3caf8414c94a&#8221;<br \/>\n}<br \/>\n}<br \/>\nIf you select the Enable Private DNS Name option, the standard AWS KMS DNS hostname (https:\/\/kms.<region>.amazonaws.com) resolves to your VPC endpoint.<\/div>\n<p><\/strong><\/span> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>A corporate cloud security policy states that communications between the company&#039;s VPC and KMS must travel entirely within the AWS network and not use public service endpoints. Which combination of the following actions MOST satisfies this requirement? (Choose two.) A. Add the aws:sourceVpcecondition to the AWS KMS key policy referencing the company&#039;s VPC endpoint ID. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,129],"class_list":["post-133","post","type-post","status-publish","format-standard","hentry","category-aws-certified-security-specialty-scs-c01","tag-aws-certified-security-specialty-scs-c01","tag-question-126"],"_links":{"self":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts\/133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/comments?post=133"}],"version-history":[{"count":0,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts\/133\/revisions"}],"wp:attachment":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/media?parent=133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/categories?post=133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/tags?post=133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}