Amazon
SCS-C03 · Question #62
A company has an encrypted Amazon Aurora DB cluster in the us-east-1 Region that uses an AWS KMS customer managed key. The company must copy a DB snapshot to the us-west-1 Region but cannot access the
Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #62. The question stem and answer options stay visible for context.
Submitted by yasin.bd· Mar 6, 2026Data Protection
Question
A company has an encrypted Amazon Aurora DB cluster in the us-east-1 Region that uses an AWS KMS customer managed key. The company must copy a DB snapshot to the us-west-1 Region but cannot access the encryption key across Regions. What should the company do to properly encrypt the snapshot in us-west-1?
Options
- AStore the customer managed key in AWS Secrets Manager in us-west-1.
- BCreate a new customer managed key in us-west-1 and use it to encrypt the snapshot.
- CCreate an IAM policy to allow access to the key in us-east-1 from us-west-1.
- DCreate an IAM policy that allows RDS in us-west-1 to access the key in us-east-1.
Unlock SCS-C03 to see the answer
You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#KMS cross-region#Aurora snapshot encryption#customer managed key#RDS snapshot copy