nerdexam
Amazon

DEA-C01 · Question #186

A company uses Amazon S3 to store data and Amazon QuickSight to create visualizations, The company has an S3 bucket in an AWS account named Hub-Account. The S3 bucket is encrypted by an AWS Key Manage

Sign in or unlock DEA-C01 to reveal the answer and full explanation for question #186. The question stem and answer options stay visible for context.

Data Security and Governance

Question

A company uses Amazon S3 to store data and Amazon QuickSight to create visualizations, The company has an S3 bucket in an AWS account named Hub-Account. The S3 bucket is encrypted by an AWS Key Management Service (AWS KMS) key. The company's QuickSight instance is in a separate account named BI-Account. The company updates the S3 bucket policy to grant access to the QuickSight service role. The company wants to enable cross-account access to allow QuickSight to interact with the S3 bucket. Which combination of steps will meet this requirement? (Choose two.)

Options

  • AUse the existing AWS KMS key to encrypt connections from QuickSight to the S3 bucket.
  • BAdd the S3 bucket as a resource that the QuickSight service role can access.
  • CUse AWS Resource Access Manager (AWS RAM) to share the S3 bucket with the BI-Account
  • DAdd an IAM policy to the QuickSight service role to give QuickSight access to the KMS key that
  • EAdd the KMS key as a resource that the QuickSight service role can access.

Unlock DEA-C01 to see the answer

You've previewed enough free DEA-C01 questions. Unlock DEA-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Cross-account access#KMS key policies#S3 encryption#QuickSight integration
Full DEA-C01 Practice