In a multi-account AWS Organization, the sales account stores petabytes in an S3 bucket encrypted with a KMS key. The marketing account uses Amazon QuickSight and needs access to the sales S3 data. Marketing has already created the QuickSight service role in its account. You must provide secure cross-account access with the least operational overhead. Which solution is best?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an IAM role in the sales account that grants access to the S3 bucket. From the marketing account, assume that IAM role to access the sales S3 bucket. Update the QuickSight role to trust and use the new IAM role in the sales account..
Why this is the answer
Creating an IAM role in the sales account with access to the S3 bucket and allowing the QuickSight role in the marketing account to assume it is the most secure and least overhead solution. This establishes a trust relationship, enabling cross-account access without duplicating data or broadly sharing resources. The QuickSight role in the marketing account can then assume this role to access the sales S3 bucket and decrypt data using the sales account's KMS key (assuming the S3 bucket policy and KMS key policy allow the assumed role to perform these actions). Replicating the S3 bucket increases storage costs and operational overhead. Using an SCP is for setting maximum permissions, not granting specific access. Updating the S3 bucket policy in the marketing account is incorrect because the bucket is in the sales account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed