passdrill
AWS SAA-C03 · S3 & Storage · Card 040/044 hard

Account A wants to replicate SSE-KMS encrypted objects from its bucket to a bucket owned by Account B, encrypting the replicas with a KMS key in Account B. Beyond meeting the general replication requirements, which two additional conditions must be satisfied for this cross-account, KMS-encrypted replication to work?

  1. The replication rule must opt in to replicating KMS-encrypted objects and specify Account B's key; separately, Account B must grant Account A's replication role permission in that key's key policy — and the key must be a customer managed key, since AWS managed keys cannot be used cross-account
  2. Nothing extra is required beyond enabling versioning on both buckets, since KMS-encrypted objects replicate identically to unencrypted ones
  3. Account A must switch the source bucket to SSE-S3 encryption before replication will process any objects
  4. Account B must make its bucket fully public so Account A's replication role can reach it without a key policy grant
Next card → Shuffle