Bắt đầu ngayBắt đầu miễn phí

Choose the key, then live with it

A new bucket holds the nightly export, and it is going on SSE-KMS rather than the default, so that key use shows up in CloudTrail. Two things are already asked of it: partner account 999988887777 has to be able to decrypt, and the security review wants the material replaced every ninety days.

Open the Key custody console. Choose aws/s3 first, because it is the key you are offered without creating one of your own, and work both steps underneath it. Read each refusal.

Then switch to alias/reports and work the same two steps again.

The strip on the right lists what the two keys share, so ignore anything on it.

Select the two things alias/reports let you do that aws/s3 refused.

Bài tập này là một phần của khóa học

Using AWS Security for Developers

Xem khóa học

Bài tập tương tác thực hành

Biến lý thuyết thành hành động với một trong các bài tập tương tác của chúng tôi

Bắt đầu bài tập