Topic 1 Question 271
2 つ選択A company uses an organization in AWS Organizations that has all features enabled. The company uses AWS Backup in a primary account and uses an AWS Key Management Service (AWS KMS) key to encrypt the backups.
The company needs to automate a cross-account backup of the resources that AWS Backup backs up in the primary account. The company configures cross-account backup in the Organizations management account. The company creates a new AWS account in the organization and configures an AWS Backup backup vault in the new account. The company creates a KMS key in the new account to encrypt the backups. Finally, the company configures a new backup plan in the primary account. The destination for the new backup plan is the backup vault in the new account.
When the AWS Backup job in the primary account is invoked, the job creates backups in the primary account. However, the backups are not copied to the new account's backup vault.
Which combination of steps must the company take so that backups can be copied to the new account's backup vault?
Edit the backup vault access policy in the new account to allow access to the primary account.
Edit the backup vault access policy in the primary account to allow access to the new account.
Edit the backup vault access policy in the primary account to allow access to the KMS key in the new account.
Edit the key policy of the KMS key in the primary account to share the key with the new account.
Edit the key policy of the KMS key in the new account to share the key with the primary account.
ユーザの投票
コメント(12)
- 正解だと思う選択肢: AD
https://docs.aws.amazon.com/aws-backup/latest/devguide/create-cross-account-backup.html
In your destination account, you must create a backup vault. Then, you assign a customer managed key to encrypt backups in the destination account, and a resource-based access policy to allow AWS Backup to access the resources you would like to copy. In the source account, if your resources are encrypted with a customer managed key, you must share this customer managed key with the destination account. You can then create a backup plan and choose a destination account that is part of your organizational unit in AWS Organizations.
👍 8auxwww2024/07/31 - 正解だと思う選択肢: AD
backup a backup using aws backup to backup account :) AD second paragraph: https://docs.aws.amazon.com/aws-backup/latest/devguide/create-cross-account-backup.html
👍 5xdkonorek22024/07/06 - 正解だと思う選択肢: AE
A: Ensures the primary account can access the backup vault in the new account. E: Ensures the primary account can use the KMS key in the new account for encryption.
👍 4trungtd2024/07/14
シャッフルモード