What should the company do next to meet these requirements?

2 Comments

  1. Sandra
    Author

    As far as I can tell, the answer is:
    Create a key policy that allows the kms:Decrypt action only for Amazon S3, DynamoDB, Lambda, and Amazon EKS. Create an AWS Config rule to send alerts for resources that are not encrypted with the key.

  2. Sara
    Author

    From what I’ve seen, the answer is:
    Create a key policy that allows the kms:Decrypt action only for Amazon S3, DynamoDB, Lambda, and Amazon EKS. Create an AWS Config rule to send alerts for resources that are not encrypted with the key.

Leave a Reply to Sara Cancel reply

Your email address will not be published. Required fields are marked *

6 − 3 =