QuestionQ12

Identity and Access Management

A security team manages a company’s AWS Key Management Service (AWS KMS) customer managed keys. Only members of the security team can administer the KMS keys. The company’s application team has a software process that occasionally requires temporary access to the keys. The security team must provide that software process with access to the keys.

Which solution meets these requirements with the LEAST operational overhead?

Explanation

AWS KMS grants provide a scoped, temporary way to allow an AWS principal to use a KMS key for specified cryptographic operations without changing the key policy or IAM policies. The security team can revoke the grant when access is no longer required, while retaining key-administration control. Grants in AWS KMS

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!