Study. uk . com
  1. Home
  2. All questions
  3. Question 60

AWS Certified Solutions Architect study material · question 60 of 500

Why do AWS services that encrypt data at rest typically use a KMS grant rather than editing the key policy?

  1. A grant can be created, used and retired without changing any policy
  2. A grant can deny access that a key policy allows
  3. A grant applies to every key in the account at once
  4. A grant survives deletion of the KMS key
Show the answer

Answer: A. A grant can be created, used and retired without changing any policy

Grants suit temporary permission: the service creates one on the user's behalf, uses it, and retires it when the work finishes.

Source: Grants in AWS KMS (Amazon Web Services) — Grants in AWS KMS

Challenge yourself on this topic → Study as cards