Your application runs in us-west-1 and you want redundancy in us-east-1. The application secrets are stored in AWS Secrets Manager in us-west-1. How can you replicate those secrets to us-east-1?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable secret replication for each secret: add us-east-1 as a replication Region and select an AWS KMS key in us-east-1 to encrypt the replicated secrets..
Why this is the answer
AWS Secrets Manager natively supports multi-Region replication. To replicate secrets, you enable replication for each secret individually, specifying the target Region (us-east-1 in this case) and selecting an AWS Key Management Service (KMS) key within that target Region to encrypt the replicated secret. This ensures the secret is encrypted with a key managed in the destination Region, maintaining regional security isolation. The incorrect options propose less efficient or unsupported methods. Creating new secrets and enabling replication from the source with a source KMS key is incorrect because the replicated secret must use a KMS key from its own Region. Secrets Manager does not have "replication rules" or integrate with secret rotation for replication in the manner described. Exporting secrets to S3 and using S3 replication is a manual, less secure, and complex workaround compared to the built-in Secrets Manager replication feature.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed