An organization uses AWS Organizations (all features enabled) and AWS Backup in a primary account that encrypts backups with a KMS key. The company set up cross-account backups to a new account's backup vault and created a KMS key in the new account. When a backup job runs in the primary account, backups are created locally but are not copied to the new account's vault. Which steps must be taken so backups can be copied to the new account's backup vault? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Edit the backup vault access policy in the new account to allow the primary account access., Edit the key policy of the KMS key in the primary account to grant the new account permissions to use the key..
Why this is the answer
For cross-account backups to succeed, two main permissions are required. First, the backup vault in the destination (new) account needs a resource-based policy that explicitly allows the source (primary) account to write backups to it. This is why editing the backup vault access policy in the new account is critical. Second, the KMS key used to encrypt the original backup in the primary account must grant the new account permission to decrypt and re-encrypt the backup data as it's copied. Without this, the new account cannot access the encrypted data. The other options are incorrect because the primary account's vault policy doesn't govern cross-account writes, and the new account's KMS key isn't used for the initial encryption in the primary account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed