exam questions

Exam AWS Certified DevOps Engineer - Professional DOP-C02 All Questions

View all questions & answers for the AWS Certified DevOps Engineer - Professional DOP-C02 exam

Exam AWS Certified DevOps Engineer - Professional DOP-C02 topic 1 question 271 discussion

A company uses an organization in AWS Organizations that has all features enabled. The company uses AWS Backup in a primary account and uses an AWS Key Management Service (AWS KMS) key to encrypt the backups.

The company needs to automate a cross-account backup of the resources that AWS Backup backs up in the primary account. The company configures cross-account backup in the Organizations management account. The company creates a new AWS account in the organization and configures an AWS Backup backup vault in the new account. The company creates a KMS key in the new account to encrypt the backups. Finally, the company configures a new backup plan in the primary account. The destination for the new backup plan is the backup vault in the new account.

When the AWS Backup job in the primary account is invoked, the job creates backups in the primary account. However, the backups are not copied to the new account's backup vault.

Which combination of steps must the company take so that backups can be copied to the new account's backup vault? (Choose two.)

  • A. Edit the backup vault access policy in the new account to allow access to the primary account.
  • B. Edit the backup vault access policy in the primary account to allow access to the new account.
  • C. Edit the backup vault access policy in the primary account to allow access to the KMS key in the new account.
  • D. Edit the key policy of the KMS key in the primary account to share the key with the new account.
  • E. Edit the key policy of the KMS key in the new account to share the key with the primary account.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
auxwww
Highly Voted 6 months, 1 week ago
Selected Answer: AD
https://docs.aws.amazon.com/aws-backup/latest/devguide/create-cross-account-backup.html In your destination account, you must create a backup vault. Then, you assign a customer managed key to encrypt backups in the destination account, and a resource-based access policy to allow AWS Backup to access the resources you would like to copy. In the source account, if your resources are encrypted with a customer managed key, you must share this customer managed key with the destination account. You can then create a backup plan and choose a destination account that is part of your organizational unit in AWS Organizations.
upvoted 8 times
...
xdkonorek2
Highly Voted 7 months ago
Selected Answer: AD
backup a backup using aws backup to backup account :) AD second paragraph: https://docs.aws.amazon.com/aws-backup/latest/devguide/create-cross-account-backup.html
upvoted 5 times
...
teo2157
Most Recent 3 weeks ago
Selected Answer: AD
@auxwww expplanation is perfect
upvoted 2 times
...
luisfsm_111
1 month, 4 weeks ago
Selected Answer: AE
In my view, D is not needed because the backups in the new account will use the KMS key in the new account, not the primary account’s key.
upvoted 1 times
...
auxwww
3 months, 3 weeks ago
Selected Answer: AD
A,D - Correct "n your destination account, you must create a backup vault. Then, you assign a customer managed key to encrypt backups in the destination account, and a resource-based access policy to allow AWS Backup to access the resources you would like to copy. In the source account, if your resources are encrypted with a customer managed key, you must share this customer managed key with the destination account. You can then create a backup plan and choose a destination account that is part of your organizational unit in AWS Organizations."
upvoted 3 times
...
limelight04
5 months, 1 week ago
Selected Answer: AE
Option A: Edit the backup vault access policy in the new account to allow access to the primary account. This step ensures that the primary account has the necessary permissions to copy backups into the new account’s backup vault. Option E: Edit the key policy of the KMS key in the new account to share the key with the primary account. This step allows the primary account to use the KMS key in the new account for encryption during the backup copy process
upvoted 1 times
...
[Removed]
5 months, 2 weeks ago
Selected Answer: AD
vote for AD
upvoted 4 times
...
jamesf
6 months, 1 week ago
Selected Answer: AE
I prefer AE as 1. the company need cross-account backup but not cross-account copy. 2. And the KMS key created in new account for backup encryption. highlighted keys: - The company configures cross-account backup in the Organizations management account. - The company creates a new AWS account in the organization and configures an AWS Backup backup vault in the new account. - The company creates a KMS key in the new account to encrypt the backups. - Finally, the company configures a new backup plan in the primary account. - The destination for the new backup plan is the backup vault in the new account.
upvoted 2 times
jamesf
6 months, 1 week ago
A. Edit the backup vault access policy in the new account to allow access from the primary account. E. Edit the key policy of the KMS key in the new account to share the key with the primary account. Backup Plan and Resource located in Management Account. Backup Vault and KMS Key located in new account. Based on URLs below, still confusing as the KMS key in new account (Destination) already https://docs.aws.amazon.com/aws-backup/latest/devguide/create-cross-account-backup.html https://repost.aws/knowledge-center/backup-troubleshoot-cross-account-copy Hope someone choose option D can explain further why option D but not E.
upvoted 1 times
...
jamesf
6 months ago
Seen like D correct - For the resources that aren't fully managed by AWS Backup, the backups use the same KMS key as the source resource. - For the resources that are fully managed by AWS Backup, the backups are encrypted with encryption key of the backup vault. https://repost.aws/knowledge-center/backup-troubleshoot-cross-account-copy
upvoted 1 times
...
...
d9iceguy
6 months, 2 weeks ago
Selected Answer: AD
D - https://docs.aws.amazon.com/aws-backup/latest/devguide/create-cross-account-backup.html#backup-cab-encryption During a cross-account copy, the source account KMS key policy must allow the destination account on the KMS key policy.
upvoted 4 times
...
inturist
6 months, 3 weeks ago
Selected Answer: AD
A, D https://docs.aws.amazon.com/aws-backup/latest/devguide/create-cross-account-backup.html
upvoted 4 times
...
trungtd
6 months, 3 weeks ago
Selected Answer: AE
A: Ensures the primary account can access the backup vault in the new account. E: Ensures the primary account can use the KMS key in the new account for encryption.
upvoted 4 times
...
siheom
6 months, 4 weeks ago
Selected Answer: AE
VOTE AE
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago