ExamQuestions.com

Register
Login
AWS Certified Security Specialty Exam Questions

Amazon

AWS Certified Security Specialty

280 / 310

Question 280:

You’re planning to use Kinesis Data Firehose. The data would be sent to an S3 bucket. The data would be encrypted at rest using a KMS key. You need to create an IAM role with suitable IAM policies to grant Kinesis Data Firehose access to the S3 bucket. Which of the following permissions need to be included in the IAM policies? (Select TWO.)

Answer options:

A.Kms:Decrypt
B.Kms:Import-key-material
C.Kms:GenerateCustomerKey
D.Kms:GenerateDataKey