exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 401 discussion

A SysOps administrator wants to share a copy of a production database with a migration account. The production database is hosted on an Amazon RDS DB instance and is encrypted at rest with an AWS Key Management Service (AWS KMS) key that has an alias of production-rds-key.

What must the SysOps administrator do to meet these requirements with the LEAST administrative overhead?

  • A. Take a snapshot of the RDS DB instance in the production account. Amend the KMS key policy of the production-rds-key KMS key to give access to the migration account's root user. Share the snapshot with the migration account.
  • B. Create an RDS read replica in the migration account. Configure the KMS key policy to replicate the production-rds-key KMS key to the migration account.
  • C. Take a snapshot of the RDS DB instance in the production account. Share the snapshot with the migration account. In the migration account, create a new KMS key that has an identical alias.
  • D. Use native database toolsets to export the RDS DB instance to Amazon S3. Create an S3 bucket and an S3 bucket policy for cross account access between the production account and the migration account. Use native database toolsets to import the database from Amazon S3 to a new RDS DB instance.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nharaz
Highly Voted 10 months ago
Selected Answer: A
https://repost.aws/knowledge-center/share-encrypted-rds-snapshot-kms-key
upvoted 7 times
...
Kipalom
Highly Voted 10 months ago
Selected Answer: A
As its not possible to create a read replica in another account, I go for A. Make a snapshot, make sure the migration account kann use the KMS key and share the snapshot for decryption.
upvoted 5 times
March2023
8 months, 1 week ago
https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/automate-the-replication-of-amazon-rds-instances-across-aws-accounts.html
upvoted 2 times
...
...
LemonGremlin
Most Recent 10 months ago
Selected Answer: B
Option B is generally more straightforward, as it leverages RDS read replicas and KMS key replication to achieve the goal without the need for complex manual snapshot sharing or exporting/importing data.
upvoted 2 times
magistrum
8 months, 2 weeks ago
only question i have is the copy is a read only replica...can't do much else if they need to write to it as part of migration....
upvoted 1 times
...
...
WinAndWin
10 months ago
Selected Answer: B
- C, D are not correct. - I think B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago