Infrastructure Security Flashcards
1
Q
You are setting up guarduty to write encrypted data to s3 what three permission types do you need to add ?
A
1 - S3 policy - to allow Guardduty to use the bucket
2 - Key Policy - to allow Guardduty to use the CMK
3 - Addition to the key policy to allow Guardduty to generate a data key
2
Q
What is a key policy in KMS ?
A
A reource based policy that controls access to the CMK