The company must encrypt all AMIs that are shared across accounts. You have an unencrypted custom AMI in the source account, and an Auto Scaling group in the target account will launch EC2 instances from the AMI. A KMS key exists in the source account. Which additional steps are required? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: In the source account, copy the unencrypted AMI to create an encrypted AMI and specify the source-account KMS key in the AMI copy operation., In the source account, update the KMS key policy to allow the target account to create grants. Then, in the target account, create a KMS grant that delegates permissions to the Auto Scaling service-linked role., In the source account, share the encrypted AMI with the target account..
Why this is the answer
To use an encrypted AMI across accounts, you must first encrypt it. Copying the unencrypted AMI to an encrypted one using a customer-managed KMS key in the source account is the correct first step. Sharing an unencrypted AMI would not meet the encryption requirement. Sharing the encrypted AMI with the target account allows the target account to access it. Finally, for the Auto Scaling group in the target account to launch instances from the encrypted AMI, it needs permission to use the source-account KMS key. Updating the source KMS key policy to allow the target account to create grants, and then creating a grant in the target account for the Auto Scaling service-linked role, provides the necessary cross-account KMS key usage permissions. Specifying the default Amazon EBS encryption key would not use the required source-account KMS key. Creating a KMS grant directly in the source account for a target-account role is not the standard cross-account KMS sharing mechanism.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed