A company stores sensitive documents in Amazon S3 by using server-side encryption with an IAM Key Management Service (IAM KMS) CMK. A new requirement mandates that the CMK that is used for these documents can be used only for S3 actions.
Which statement should the company add to the key policy to meet this requirement?
A)

B)

To ensure minimal latency and regional availability of secrets, encrypting secrets in us-east-1 with a customer-managed KMS key and then replicating them to us-west-1 for encryption with the same key is the optimal approach. This method leverages customer-managed KMS keys for enhanced control and ensures that secrets are available in both regions, adhering to disaster recovery principles and minimizing latency by using regional endpoints.
Eloisa
8 months agoNiesha
8 months agoJustine
8 months agoRodney
8 months agoSheldon
9 months agoGeraldine
9 months agoGlenn
9 months agoLeatha
9 months agoJesusita
9 months agoMelvin
9 months agoHannah
9 months agoGertude
9 months agoCorrie
10 months agoAnisha
10 months agoJose
10 months agoGarry
10 months agoJerlene
10 months agoDerick
1 year agoCasey
1 year agoTheola
1 year agoNickolas
1 year agoKristin
1 year agoSarina
1 year agoOtis
1 year agoDino
1 year agoLawrence
1 year agoAshlee
1 year agoJordan
1 year agoJames
1 year agoJackie
1 year agoGary
1 year agoLawanda
1 year agoPearly
1 year agoSue
1 year agoLavonna
1 year ago