Your company has two AWS accounts: production (hosts the source S3 bucket) and development (destination S3 bucket). Data in the production bucket is encrypted with a customer-managed AWS KMS key. You will copy the data into the development account’s S3 bucket and must use a KMS key in the development account to encrypt the copied data. That KMS key in development must allow access from the production account. Which approach satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new customer-managed KMS key in the development account and include the production account in that key’s policy..
Why this is the answer
The correct approach is to create a new customer-managed KMS key in the development account and include the production account in its key policy. This allows the production account to encrypt data using the development account's KMS key during the copy operation, satisfying the requirement that the copied data be encrypted with a development account KMS key. KMS keys are regional and cannot be directly replicated across accounts. Creating an AWS-managed KMS key for Amazon S3 (Option C) would not allow you to modify its key policy to grant cross-account access. Replicating any KMS key (Options A and D) is not a valid KMS operation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed