Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Developer - Associate DVA-C02 Question # 152 Topic 16 Discussion

Amazon Web Services AWS Certified Developer - Associate DVA-C02 Question # 152 Topic 16 Discussion

DVA-C02 Exam Topic 16 Question 152 Discussion:
Question #: 152
Topic #: 16

A developer is using an AWS account to build an application that stores files in an Amazon S3 bucket. Files must be encrypted at rest by AWS KMS keys. A second AWS account must have access to read files from the bucket.

The developer wants to minimize operational overhead for the application.

Which combination of solutions will meet these requirements? (Select TWO.)


A.

Use a customer managed key to encrypt the files. Create a key policy that grants kms: Decrypt permissions to the second AWS account.


B.

Use an AWS managed key to encrypt the files. Create a key policy that grants kms:Decrypt permissions to the second AWS account.


C.

Create a service control policy (SCP) that grants s3:GetObject permissions to the second AWS account.


D.

Create a bucket policy for the S3 bucket that grants s3:GetObject permissions to the second AWS account.


E.

Create a gateway endpoint for the S3 bucket. Modify the endpoint policy to grant s3:GetObject permissions to the second AWS account.


Get Premium DVA-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.