KMS keys protect AI logs and data.
Limit who can decrypt.
Choose two designs.
Restrict key use by principal, purpose, resource, condition, and time, and monitor use, denials, administration, review, and emergency disablement.
Detailed explanation
Unneeded decryption is blocked.
Unneeded decryption is blocked.
Misuse can be detected and stopped.
Misuse can be detected and stopped.
Least privilege is violated.
Least privilege is violated.
Attack signals are missed.
Attack signals are missed.
Try it yourself
An example you can run in a temporary verification environment.
AWS公式AIF-C01 Domain 5.2のKMS、IAM、鍵アクセス監視を確認する。Expected result
暗号化を鍵の保護まで含むアクセス制御として運用できる。Key points
- Key access
- IAM
- Denial log
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.