Multiple Choice
A corporate cloud security policy states that communications between the company's VPC and KMS must travel entirely within the AWS network and not use public service endpoints. Which combination of the following actions MOST satisfies this requirement? (Choose two.)
A) Add the aws:sourceVpce condition to the AWS KMS key policy referencing the company's VPC endpoint ID. Add the aws:sourceVpce condition to the AWS KMS key policy referencing the company's VPC endpoint ID.
B) Remove the VPC internet gateway from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity.
C) Create a VPC endpoint for AWS KMS with private DNS enabled.
D) Use the KMS Import Key feature to securely transfer the AWS KMS key over a VPN.
E) Add the following condition to the AWS KMS key policy: "aws:SourceIp": "10.0.0.0/16". Add the following condition to the AWS KMS key policy: "aws:SourceIp": "10.0.0.0/16".
Correct Answer:

Verified
Correct Answer:
Verified
Q198: A security alert has been raised for
Q199: A company needs a forensic-logging solution for
Q200: A company stores data on an Amazon
Q201: A water utility company uses a number
Q202: A public subnet contains two Amazon EC2
Q204: A company's database developer has just migrated
Q205: Due to new compliance requirements, a Security
Q206: A company plans to use custom AMIs
Q207: A company wants to control access to
Q208: A company had one of its Amazon