Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 70 discussion

A company is partnering with an external vendor to provide data processing services. For this integration, the vendor must host the company's data in an Amazon
S3 bucket in the vendor's AWS account. The vendor is allowing the company to provide an AWS Key Management Service (AWS KMS) key to encrypt the company's data. The vendor has provided an IAM role Amazon Resources Name (ARN) to the company for this integration.
What should a SysOps administrator do to configure this integration?

  • A. Create a new KMS key. Add the vendor's IAM role ARN to the KMS key policy. Provide the new KMS key ARN to the vendor.
  • B. Create a new KMS key. Create a new IAM key. Add the vendor's IAM role ARN to an inline policy that is attached to the IAM user. Provide the new IAM user ARN to the vendor.
  • C. Configure encryption using the KMS managed S3 key. Add the vendor's IAM role ARN to the KMS key policy. Provide the KMS managed S3 key ARN to the vendor.
  • D. Configure encryption using the KMS managed S3 key. Create an S3 bucket. Add the vendor's IAM role ARN to the S3 bucket policy. Provide the S3 bucket ARN to the vendor.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
fedorian
Highly Voted 2 years ago
Selected Answer: A
The vendor is required to host the S3 bucket. It holds the company's data. The vendor wants to use a company-provided key to encrypt the data. So the company needs to create the new key and then provide access to that key from the IAM role which was provided by the vendor. (Answer: A) D - Can't be D as that would mean the company is hosting the data (not the vendor). D is hosting the data at the company and providing access to the data to the vendor.
upvoted 20 times
...
gehadg
Most Recent 2 weeks, 3 days ago
Correct Answer: A Option A is correct because it specifies creating a new KMS key and explicitly adding the vendor's IAM role ARN to the key policy. This approach allows the vendor to use the KMS key for encryption while ensuring access control and security through the key policy. By providing the KMS key ARN to the vendor, they can use it to encrypt the data in the S3 bucket hosted in their account. Other Options: Option B creates an unnecessary IAM user and an inline policy, adding complexity without directly addressing KMS encryption needs. Option C suggests using the KMS-managed S3 key, which is controlled by AWS and does not provide the flexibility of adding external roles to the key policy. Option D configures encryption using the KMS-managed S3 key but adds the vendor's role to the S3 bucket policy rather than the KMS key policy, which would not grant the needed access to use the key for encryption.
upvoted 1 times
...
Andrew_A
1 year, 5 months ago
Selected Answer: A
By creating a new KMS key, the SysOps administrator is ensuring that the key used to encrypt the company's data is distinct and managed separately. The key policy is the primary resource-based policy that controls who can access and manage the key. By adding the vendor's IAM role ARN to the KMS key policy, the SysOps administrator is giving the vendor permissions to use the key, while keeping the control of the key. By providing the ARN of the new KMS key to the vendor, the vendor will be able to use that key to encrypt the company's data stored in the S3 bucket in the vendor's account.
upvoted 2 times
...
fts_cevans
1 year, 5 months ago
Selected Answer: A
The provided answer links to an outside practice question - But if you go to that link **THE QUESTION** is different. It's as if ExamTopics has the wrong answer assigned to this question or they've pasted the wrong question into it. As the question is written now, it's DEFINITELY *NOT* D. As others said - The S3 bucket needs to be in the vendor's account - So you would obviously not create one in YOUR account for this use.
upvoted 2 times
...
englishborn
1 year, 7 months ago
Selected Answer: A
You need to create a new KMS from the question
upvoted 2 times
...
caputmundi666
1 year, 7 months ago
Selected Answer: A
kms is in company's account. S3 is in vendor's account. Company must allow encrypt/decrypt vendor's IAM role in the KMS policy. Company should share KMS ARN of KMS. Managed S3 KMS cannot be shared, you cannot edit its policy
upvoted 3 times
...
michele_scar
1 year, 8 months ago
Selected Answer: A
The vendor has to host the S3, not your own company
upvoted 2 times
...
braveheart22
1 year, 8 months ago
A is the right option from my point of view
upvoted 2 times
...
Pacoca
1 year, 9 months ago
I agree with Fedorian So the company needs to create the new key and then provide access to that key from the IAM role which was provided by the vendor
upvoted 1 times
...
noahsark
1 year, 9 months ago
Selected Answer: A
https://www.filecloud.com/supportdocs/fcdoc/latest/server/filecloud-administrator-guide/filecloud-site-setup/storage-settings/filecloud-managed-storage/s3-storage-encryption-with-aws-cross-account-kms-key
upvoted 1 times
...
BietTuot
1 year, 11 months ago
Selected Answer: A
I vote for A. C. INCORRECT: You can't modify KMS managed S3 key policy. D. INCORRECT: Because the bucket is in the vendor's account not in the company's account. Moreover, bucket policy doesn't allow Role encrypt/decrypt data. You need to use KMS Key policy.
upvoted 3 times
...
MrMLB
1 year, 11 months ago
Selected Answer: A
A. Create a new KMS key. Add the vendor's IAM role ARN to the KMS key policy. Provide the new KMS key ARN to the vendor.
upvoted 2 times
...
tyfta6
1 year, 11 months ago
Selected Answer: A
Vote for A
upvoted 1 times
...
michaldavid
1 year, 11 months ago
Selected Answer: A
Going for A
upvoted 2 times
...
Liongeek
1 year, 12 months ago
Ans: A
upvoted 1 times
...
[Removed]
2 years ago
Selected Answer: A
It's A guys.
upvoted 3 times
zhangyu20000
2 years ago
question clearly ask to use KMS
upvoted 1 times
...
...
Surferbolt
2 years ago
Bucket is in vendor's account, encrypted using company's key. So the vendor will require permission to use key to access data.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...