What it is: A resource-based policy attached to a KMS key that controls who can use/administer the key.
What it’s for:
Key ideas:
Key policy is required for KMS authorization.
IAM policy alone may not be enough if the key policy doesn’t allow it.
Key policy can enable cross-account access to the key.
Exam cues:
Hard words:
*administer* /ədˈmɪnɪstər/: quản trị
*required* /rɪˈkwaɪərd/: bắt buộc
*authorization* /ˌɔːθərəˈzeɪʃn/: cấp quyền