A partner vendor will host a company's data inside an S3 bucket in the vendor's AWS account. The vendor has asked the company to supply a KMS key for encrypting that data and has shared an IAM role ARN that the vendor will assume. What should the SysOps administrator do to enable this integration securely?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new KMS key in the company's account, add the vendor’s IAM role ARN to that KMS key policy, and give the vendor the new KMS key ARN to use..
Why this is the answer
Creating a new KMS key in the company's account and adding the vendor's IAM role ARN to its key policy is the correct and most secure approach. This allows the company to maintain full control over the encryption key, including revoking access if needed, while granting the vendor specific permissions to use it for data encryption within their S3 bucket. The vendor then uses this key ARN when configuring their S3 bucket. Using an AWS-managed S3 KMS key is incorrect because these keys cannot have custom key policies attached, preventing the company from granting specific cross-account access to the vendor's IAM role. Creating a new IAM user and attaching an inline policy is incorrect because the vendor needs access to the KMS key, not a new IAM user from the company's account. Adding the vendor's IAM role ARN to an S3 bucket policy is incorrect because the question specifies the vendor will host the data in their S3 bucket, meaning the company's S3 bucket policy is irrelevant for encryption in the vendor's account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed