Amazon Web Services AWS Certified Data Engineer - Associate (DEA-C01) Data-Engineer-Associate Question # 49 Topic 5 Discussion

Amazon Web Services AWS Certified Data Engineer - Associate (DEA-C01) Data-Engineer-Associate Question # 49 Topic 5 Discussion

Data-Engineer-Associate Exam Topic 5 Question 49 Discussion:
Question #: 49
Topic #: 5

A company uses Amazon S3 to store data and Amazon QuickSight to create visualizations.

The company has an S3 bucket in an AWS account named Hub-Account. The S3 bucket is encrypted by an AWS Key Management Service (AWS KMS) key. The company's QuickSight instance is in a separate account named BI-Account

The company updates the S3 bucket policy to grant access to the QuickSight service role. The company wants to enable cross-account access to allow QuickSight to interact with the S3 bucket.

Which combination of steps will meet this requirement? (Select TWO.)


A.

Use the existing AWS KMS key to encrypt connections from QuickSight to the S3 bucket.


B.

Add the 53 bucket as a resource that the QuickSight service role can access.


C.

Use AWS Resource Access Manager (AWS RAM) to share the S3 bucket with the Bl-Account account.


D.

Add an IAM policy to the QuickSight service role to give QuickSight access to the KMS key that encrypts the S3 bucket.


E.

Add the KMS key as a resource that the QuickSight service role can access.


Get Premium Data-Engineer-Associate Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.