A SysOps administrator needs to share Amazon RDS snapshots between AWS accounts belonging to different business units. The snapshots must remain encrypted at rest. What approach should the administrator use to accomplish this?
Choose an answer
Tap an option to check your answer.
Correct answer: Grant the other AWS accounts permissions in the KMS key policy used to encrypt the snapshot, then share the snapshot with those accounts..
Why this is the answer
To share an encrypted RDS snapshot across accounts while maintaining encryption, the KMS key used to encrypt the snapshot must be shared. The correct approach involves modifying the KMS key policy to grant usage permissions to the target AWS accounts. Once the key policy is updated, the snapshot can be shared directly with those accounts. The target accounts can then restore the snapshot using their granted permissions to the KMS key. The other options are incorrect because: Downloading and decrypting locally breaks the encryption at rest requirement and is impractical for large snapshots. Launching an EC2 instance and creating EBS snapshots is an indirect and inefficient method not designed for RDS snapshot sharing. Restoring to an unencrypted instance and exporting data compromises the encryption requirement and is not a direct snapshot sharing mechanism.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed