After recovering EC2 instances from Amazon EBS snapshots during an incident, a company using an AWS Key Management Service (AWS KMS) customer managed key for snapshot encryption performs a disaster recovery gap analysis. The company needs a solution to recover EC2 instances even if the primary AWS account is compromised and its EBS snapshots are deleted. Which solution meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a separate, restricted AWS account. Grant that account access to the KMS key used to encrypt the EBS snapshots, and regularly copy the encrypted snapshots to the new account..
Why this is the answer
The correct solution is to create a separate, restricted AWS account and regularly copy encrypted snapshots to it, granting the new account access to the KMS key. This strategy provides isolation from a primary account compromise, as deletion in the primary account would not affect the copies in the separate account. It also ensures recoverability even if the primary account's EBS snapshots are deleted. Incorrect options: Moving EBS snapshots to S3 via lifecycle policies is not directly supported; EBS snapshots are already stored in S3-backed infrastructure. Using AWS Systems Manager to back up disks to S3 is not the standard or most efficient way to manage EBS snapshot backups for disaster recovery. EBS snapshots are already block-level backups. AWS Backup can manage EBS snapshots, but simply copying them to S3 within the same account and enabling S3 Object Lock doesn't protect against a full account compromise where all resources, including S3 buckets, could be affected or deleted by an attacker with root access. The key is account isolation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed