[Identity and Access Management]
A company's engineering team is developing a new application that creates IAM Key Management Service (IAM KMS) CMK grants for users immediately after a grant IS created users must be able to use the CMK tu encrypt a 512-byte payload. During load testing, a bug appears |intermittently where AccessDeniedExceptions are occasionally triggered when a userrst attempts to encrypt using the CMK
Which solution should the c0mpany's security specialist recommend'?
To avoid AccessDeniedExceptions when users first attempt to encrypt using the CMK, the security specialist should recommend the following solution:
Instruct the engineering team to pass the grant token returned in the CreateGrant response to users. This allows the engineering team to use the grant token as a form of temporary authorization for the grant.
Instruct users to use that grant token in their call to encrypt. This allows the users to use the grant token as a proof that they have permission to use the CMK, and to avoid any eventual consistency issues with the grant creation.
Letha
15 days agoMeghan
20 days agoRosalind
25 days agoHalina
1 month agoAdolph
1 month agoAlbina
2 months agoAriel
2 months agoParis
2 months agoElfrieda
2 months agoRuthann
2 months agoTracey
3 months agoDannie
3 months agoElliot
3 months agoTamesha
3 months agoLigia
3 months agoAntonette
4 months agoLindsey
4 months agoDella
4 months agoFelicitas
4 months agoBrittani
4 months agoWilda
5 months agoJoana
5 months agoRodolfo
5 months agoChaya
5 months agoBuddy
4 days agoKatie
10 days ago