ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 176 - DOP-C02 discussion

Report
Export

A company uses an organization in AWS Organizations that has all features enabled. The company uses AWS Backup in a primary account and uses an AWS Key Management Service (AWS KMS) key to encrypt the backups.

The company needs to automate a cross-account backup of the resources that AWS Backup backs up in the primary account. The company configures cross-account backup in the Organizations management account. The company creates a new AWS account in the organization and configures an AWS Backup backup vault in the new account. The company creates a KMS key in the new account to encrypt the backups. Finally, the company configures a new backup plan in the primary account. The destination for the new backup plan is the backup vault in the new account.

When the AWS Backup job in the primary account is invoked, the job creates backups in the primary account. However, the backups are not copied to the new account's backup vault.

Which combination of steps must the company take so that backups can be copied to the new account's backup vault? (Select TWO.)

A.
Edit the backup vault access policy in the new account to allow access to the primary account.
Answers
A.
Edit the backup vault access policy in the new account to allow access to the primary account.
B.
Edit the backup vault access policy in the primary account to allow access to the new account.
Answers
B.
Edit the backup vault access policy in the primary account to allow access to the new account.
C.
Edit the backup vault access policy in the primary account to allow access to the KMS key in the new account.
Answers
C.
Edit the backup vault access policy in the primary account to allow access to the KMS key in the new account.
D.
Edit the key policy of the KMS key in the primary account to share the key with the new account.
Answers
D.
Edit the key policy of the KMS key in the primary account to share the key with the new account.
E.
Edit the key policy of the KMS key in the new account to share the key with the primary account.
Answers
E.
Edit the key policy of the KMS key in the new account to share the key with the primary account.
Suggested answer: A, E

Explanation:

To enable cross-account backup, the company needs to grant permissions to both the backup vault and the KMS key in the destination account. The backup vault access policy in the destination account must allow the primary account to copy backups into the vault. The key policy of the KMS key in the destination account must allow the primary account to use the key to encrypt and decrypt the backups.These steps are described in the AWS documentation12. Therefore, the correct answer is A and E.

1: Creating backup copies across AWS accounts - AWS Backup

2: Using AWS Backup with AWS Organizations - AWS Backup

asked 16/09/2024
Ralitsa Yankova
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first