exam questions

Exam AWS DevOps Engineer Professional All Questions

View all questions & answers for the AWS DevOps Engineer Professional exam

Exam AWS DevOps Engineer Professional topic 1 question 12 discussion

Exam question from Amazon's AWS DevOps Engineer Professional
Question #: 12
Topic #: 1
[All AWS DevOps Engineer Professional Questions]

A DevOps Engineer needs to back up sensitive Amazon S3 objects that are stored within an S3 bucket with a private bucket policy using the S3 cross-region replication functionality. The objects need to be copied to a target bucket in a different AWS Region and account.
Which actions should be performed to enable this replication? (Choose three.)

  • A. Create a replication IAM role in the source account.
  • B. Create a replication IAM role in the target account.
  • C. Add statements to the source bucket policy allowing the replication IAM role to replicate objects.
  • D. Add statements to the target bucket policy allowing the replication IAM role to replicate objects.
  • E. Create a replication rule in the source bucket to enable the replication.
  • F. Create a replication rule in the target bucket to enable the replication.
Show Suggested Answer Hide Answer
Suggested Answer: ADE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JohnnieWalker
Highly Voted 3 years, 7 months ago
ADE - The replication rule is created in the source bucket
upvoted 12 times
...
Simba84
Most Recent 4 months, 4 weeks ago
Selected Answer: ADE
ADE is correct
upvoted 1 times
...
Dgix
1 year, 6 months ago
ACE. The alternative D - "Add statements to the target bucket policy allowing the replication IAM role to replicate objects" might be chosen frequently due to a common misconception. When setting up cross-region replication in AWS S3, some people might assume that the target bucket (where the objects are being replicated to) also needs to explicitly grant permissions to the replication IAM ___role___. However, this is not the case in AWS S3 cross-region replication setup.
upvoted 1 times
...
tschenhau
1 year, 11 months ago
Selected Answer: ADE
S3 cross-Region replication (CRR) automatically replicates data between buckets across different AWS Regions. To enable CRR, you need to add a replication configuration to your source bucket that specifies the destination bucket, the IAM role, and the encryption type (optional). You also need to grant permissions to the IAM role to perform replication actions on both the source and destination buckets. Additionally, you can choose the destination storage class and enable additional replication options such as S3 Replication Time Control (S3 RTC) or S3 Batch Replication. https://medium.com/cloud-techies/s3-same-region-replication-srr-and-cross-region-replication-crr-34d446806bab https://aws.amazon.com/getting-started/hands-on/replicate-data-using-amazon-s3-replication/ https://docs.aws.amazon.com/AmazonS3/latest/userguide/replication.html
upvoted 1 times
...
nicat
1 year, 11 months ago
Selected Answer: ACE
ACE Create and attach the S3 bucket policy in the source account https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/copy-data-from-an-s3-bucket-to-another-account-and-region-by-using-the-aws-cli.html
upvoted 1 times
...
ParagSanyashiv
1 year, 12 months ago
Selected Answer: ADE
ADE seems to be correct answer
upvoted 1 times
...
mgonblan
2 years ago
D, B, E: Refference: https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/copy-data-from-an-s3-bucket-to-another-account-and-region-by-using-the-aws-cli.html
upvoted 1 times
...
Tika01
2 years, 1 month ago
ABCE are correct asnwers
upvoted 1 times
...
ccienetrider
2 years, 1 month ago
ADE - Correct Answer , Tested and working
upvoted 2 times
...
m00lecule
2 years, 2 months ago
Selected Answer: ADE
ADE - The replication rule is created in the source bucket
upvoted 1 times
...
Sabreen_Salama
2 years, 2 months ago
The answer is ADE
upvoted 1 times
...
Piccaso
2 years, 2 months ago
Selected Answer: BCE
1. B from (A, B) : the new IAM role should belong to the target account 2. C from (C, D): the policy is used to allow the role to do something to the object what the policy is attached to. 3. E from (E, F): the rule should be created to the bucket whose objects will be replicated
upvoted 2 times
Piccaso
2 years, 2 months ago
My voted answers are wrong. Sorry guys. The permission to replicate should belong to the role on source account --> A from (A, B) The target bucket policy should have statement to grant permission for replicating to the role in the source account. AWS official article: https://docs.aws.amazon.com/AmazonS3/latest/userguide/replication-walkthrough-2.html The Replication Rule should be created on the target bucket --> F from(E, F). Please refer to this article which involves screenshots of hands-on experiment. https://aws.plainenglish.io/set-up-an-s3-bucket-with-cross-region-replication-97d43084ff36
upvoted 3 times
...
...
Bulti
2 years, 3 months ago
ADE is the correct answer. To enable cross account replication we need to 1. create a replication rule in the source bucket 2. Create an IAM role in the source account to perform replication 3. Create a resource policy on the destination bucket that grant permission to the IAM role in the source account to replicate objects into the destination bucket.
upvoted 4 times
...
ohcn
2 years, 7 months ago
ADE - https://docs.aws.amazon.com/AmazonS3/latest/userguide/replication-walkthrough-2.html
upvoted 1 times
...
colinquek
2 years, 7 months ago
BDE - B becos the source acct should assume the target acct's IAM role to copy things into it.
upvoted 3 times
...
SHAAHIBHUSHANAWS
2 years, 10 months ago
ADE https://docs.aws.amazon.com/AmazonS3/latest/userguide/replication-walkthrough-2.html
upvoted 3 times
...
blueorca
3 years, 2 months ago
Selected Answer: ADE
ADE should be the answer. F is incorrect.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago