nerdexam
Amazon

SOA-C02 · Question #713

A company has a security AWS account and a production AWS account. The company stores API keys as a secret in AWS Secrets Manager in the security account. The company uses an AWS Key Management Servic

Sign in or unlock SOA-C02 to reveal the answer and full explanation for question #713. The question stem and answer options stay visible for context.

Submitted by javi_es· Mar 30, 2026Security and Compliance

Question

A company has a security AWS account and a production AWS account. The company stores API keys as a secret in AWS Secrets Manager in the security account. The company uses an AWS Key Management Service (AWS KMS) AWS managed key to encrypt the secret. An AWS Lambda function in the production account returns an error when the function attempts to access the secret. Which combination of actions in the security account will allow the Lambda function to access the secret? (Choose two.)

Options

  • ACreate a customer managed KMS key. Add a resource policy that allows the Lambda function to
  • BCreate a customer managed KMS key. Add a resource policy that allows the Lambda function to
  • CUpdate the AWS managed KMS key's resource policy. In the policy, allow the Lambda function to
  • DAdd a resource policy to the secret. In the policy, allow the Lambda function to perform the
  • EAdd a resource policy to the secret. In the policy, allow the Lambda function to perform the

Unlock SOA-C02 to see the answer

You've previewed enough free SOA-C02 questions. Unlock SOA-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Secrets Manager cross-account#customer managed KMS key#KMS key policy#resource-based policy
Full SOA-C02 Practice