A. Change the replication configuration to use the key in us-east-1 to encrypt the objects that are in the destination S3 bucket.
B. Grant the IAM role the kms:Encrypt permission for the key in us-east-1 that encrypts source objects.
C. Grant the IAM role the s3:GetObjectVersionForReplication permission for objects that are in the source S3 bucket.
D. Grant the IAM role the kms:Decrypt permission for the key in us-east-1 that encrypts source objects.
E. Change the key policy of the key in us-east-1 to grant the kms:Decrypt permission to the security engineer’s IAM account.
F. Grant the IAM role the kms:Encrypt permission for the key in us-west-2 that encrypts objects that are in the destination S3 bucket.
- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.
Join the Discussion
You must be logged in to post a comment.