QuestionQ13

Infrastructure Security

A corporate cloud-security policy states that communications between the company’s VPC and KMS must remain entirely within the AWS network and must not use public service endpoints.

Which combination of the following actions MOST fulfills this requirement?

Choose two
Explanation

An AWS KMS interface VPC endpoint provides private connectivity through AWS PrivateLink, so traffic between the VPC and KMS stays within the AWS network. With private DNS enabled, the standard AWS KMS hostname resolves to the interface endpoint. A KMS key-policy condition using aws:sourceVpce can restrict key access to requests made through that specific VPC endpoint, thereby enforcing use of the private path.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!