passdrill
AWS SAA-C03 · EC2 & Compute · Card 030/038 hard

A company wants to share a custom AMI, backed by EBS snapshots encrypted with a customer managed KMS key, with a second AWS account so that account can launch instances from it. What must they do?

  1. Sharing the AMI's launch permissions with the second account is sufficient by itself; encryption keys are automatically made available to any account granted launch permissions
  2. Encrypted AMIs can only ever be shared within the same AWS account; cross-account sharing of an encrypted AMI is not possible under any circumstances
  3. The company must switch the AMI's snapshots to use an AWS managed key before cross-account sharing becomes possible, since AWS managed keys support cross-account grants but customer managed keys do not
  4. The company must grant the second account launch permissions on the AMI AND update the customer managed KMS key's policy to grant that account the permissions needed to use the key (e.g., Decrypt, CreateGrant), since AWS managed keys cannot be shared across accounts at all
Next card → Shuffle