Loading...

Loading...

【所有题目】3. An Amazon Redshift Database is encrypted using KMS. A data engineer needs to use the AWS CLI to create a KMS encrypted snapshot of the database in another AWS region. Which three steps should the data engineer take to accomplish this task? (Choose three.)



<< >>
Loading...

正确答案: A, C, E

Correct answers are A, C & E,Option A as KMS keys are specific to the region and a new key needs to be created in the destination region.,Option C as the grant needs to be provided for Redshift to use the master key in the destination region,Option E as the replication needs to be enabled on the source region.,Refer AWS documentation - Cross Region KMS Encrypted Snapshot & Redshift - Copying AWS KMS-Encrypted Snapshots to Another AWS Region,When you launch an Amazon Redshift cluster, you can choose to encrypt it with a master key from the AWS Key Management Service (AWS KMS). AWS KMS keys are specific to a region. If you want to enable cross-region snapshot copy for an AWS KMS-encrypted cluster, you must configure a snapshot copy grant for a master key in the destination region so that Amazon Redshift can perform encryption operations in the destination region.,AWS KMS keys are specific to an AWS Region. If you enable copying of Amazon Redshift snapshots to another AWS Region, and the source cluster and its snapshots are encrypted using a master key from AWS KMS, you need to configure a grant for Amazon Redshift to use a master key in the destination AWS Region. This grant enables Amazon Redshift to encrypt snapshots in the destination AWS Region.,Option B is wrong as keys are specific to the region, new keys need to be created.,Option D is wrong as the grants need to be provided in the destination region,Option F is wrong as the cross-region replication needs to be enabled in the source region.

dbs_3

False

A, C, E

1

invalid_random_id

0

3