ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 276 - DBS-C01 discussion

Report
Export

An ecommerce company is running Amazon RDS for Microsoft SQL Server. The company is planning to perform testing in a development environment with production dat a. The development environment and the production environment are in separate AWS accounts. Both environments use AWS Key Management Service (AWS KMS) encrypted databases with both manual and automated snapshots. A database specialist needs to share a KMS encrypted production RDS snapshot with the development account.

Which combination of steps should the database specialist take to meet these requirements? (Select THREE.)

A.
Create an automated snapshot. Share the snapshot from the production account to the development account.
Answers
A.
Create an automated snapshot. Share the snapshot from the production account to the development account.
B.
Create a manual snapshot. Share the snapshot from the production account to the development account.
Answers
B.
Create a manual snapshot. Share the snapshot from the production account to the development account.
C.
Share the snapshot that is encrypted by using the development account default KMS encryption key.
Answers
C.
Share the snapshot that is encrypted by using the development account default KMS encryption key.
D.
Share the snapshot that is encrypted by using the production account custom KMS encryption key.
Answers
D.
Share the snapshot that is encrypted by using the production account custom KMS encryption key.
E.
Allow the development account to access the production account KMS encryption key.
Answers
E.
Allow the development account to access the production account KMS encryption key.
F.
Allow the production account to access the development account KMS encryption key.
Answers
F.
Allow the production account to access the development account KMS encryption key.
Suggested answer: B, D, E

Explanation:

Answer:: B, D, EExplanation from Amazon documents:To share an encrypted Amazon RDS snapshot with another account, you need to do the following123:Create a manual snapshot of the production database. You can't share an automated snapshot directly, but you can copy it to a manual snapshot and then share it1.Use a custom KMS encryption key for the manual snapshot. You can't share a snapshot that is encrypted using the default KMS key of the source account1.Share the snapshot with the development account by specifying the account ID of the target account1.Allow the development account to access the custom KMS key of the source account by adding the target account ID to the key policy of the source account2.Copy the shared snapshot to the development account by using a KMS key of the target account2.Therefore, option B, D, and E are the correct steps to meet the requirements. Option A is incorrect because you can't share an automated snapshot. Option C is incorrect because you can't share a snapshot that is encrypted using the default KMS key. Option F is unnecessary because the production account does not need to access the development account KMS key.

asked 16/09/2024
Jhon Doe
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first