A compliance standard requires that the people who administer encryption keys must not be able to decrypt data with them, and that the application which decrypts data must not be able to change key configuration. Which two policy arrangements implement this separation? (Choose TWO.)
Choose 2.
- A.
Place the key in a separate AWS account and give both groups the account's root credentials for emergencies.
- B.
Grant both groups full access to the key and review CloudTrail monthly for inappropriate use.
- C.
Grant the key administrators management actions such as key policy and rotation changes, without cryptographic actions.
- D.
Grant the key administrators cryptographic actions as well, so they can test the key after every change.
- E.
Grant the application role only cryptographic actions such as Decrypt and GenerateDataKey on the key.
Show answer
Answer: C, E
A KMS key policy separates management actions from cryptographic actions, so administrators can configure the key without using it and the application can use it without configuring it.
- A. Sharing root credentials concentrates privilege and destroys individual accountability.
- B. Monthly review is detective and leaves the prohibited capability in place the whole time.
- C. Management actions let administrators configure the key without any ability to decrypt data.
- D. Giving administrators cryptographic actions removes the separation the standard requires.
- E. Cryptographic actions let the application use the key without changing its configuration.
