exam questions

Exam AWS Certified Database - Specialty All Questions

View all questions & answers for the AWS Certified Database - Specialty exam

Exam AWS Certified Database - Specialty topic 1 question 14 discussion

Exam question from Amazon's AWS Certified Database - Specialty
Question #: 14
Topic #: 1
[All AWS Certified Database - Specialty Questions]

A company is hosting critical business data in an Amazon Redshift cluster. Due to the sensitive nature of the data, the cluster is encrypted at rest using AWS
KMS. As a part of disaster recovery requirements, the company needs to copy the Amazon Redshift snapshots to another Region.
Which steps should be taken in the AWS Management Console to meet the disaster recovery requirements?

  • A. Create a new KMS customer master key in the source Region. Switch to the destination Region, enable Amazon Redshift cross-Region snapshots, and use the KMS key of the source Region.
  • B. Create a new IAM role with access to the KMS key. Enable Amazon Redshift cross-Region replication using the new IAM role, and use the KMS key of the source Region.
  • C. Enable Amazon Redshift cross-Region snapshots in the source Region, and create a snapshot copy grant and use a KMS key in the destination Region.
  • D. Create a new KMS customer master key in the destination Region and create a new IAM role with access to the new KMS key. Enable Amazon Redshift cross-Region replication in the source Region and use the KMS key of the destination Region.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PietraOra
Highly Voted 3 years, 7 months ago
I think C If you want to enable cross-Region snapshot copy for an AWS KMS–encrypted cluster, you must configure a snapshot copy grant for a root key in the destination AWS Region Source-Region : configure a cross-Region snapshot for an AWS KMS–encrypted cluster In Destination AWS Region : choose the AWS Region to which to copy snapshots. https://docs.aws.amazon.com/redshift/latest/mgmt/managing-snapshots-console.html#xregioncopy-kms-encrypted-snapshot
upvoted 6 times
...
Pazzooo
Most Recent 1 year, 5 months ago
C See https://aws.amazon.com/blogs/big-data/migrate-your-amazon-redshift-cluster-to-another-aws-region/
upvoted 1 times
...
Hisayuki
1 year, 5 months ago
Selected Answer: C
For encrypted snapshots - configure cross region snapshots and additionally specify a snapshot copy grant which requires a KMS key
upvoted 1 times
...
AmbrishK
1 year, 7 months ago
Selected Answer: C
C. Enable Amazon Redshift cross-Region snapshots in the source Region, and create a snapshot copy grant and use a KMS key in the destination Region. Here's why this option is the correct choice: Enabling cross-Region snapshots in the source Region is necessary to initiate the snapshot copying process. Creating a snapshot copy grant allows you to define permissions and configurations for copying snapshots to the destination Region. It is an essential step in setting up snapshot replication. Using a KMS key in the destination Region ensures that the copied snapshots are encrypted with a key specific to that Region. This maintains data security during replication.
upvoted 1 times
...
roymunson
1 year, 8 months ago
Selected Answer: C
It*s C: https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-db-encryption.html#configure-snapshot-copy-grant It can't be (A) because when you read the docs it is written "[...] 2. In the SOURCE AWS Region, enable copying of snapshots and ...". B & D is about replication and not copying a snapshot.
upvoted 1 times
...
Germaneli
1 year, 9 months ago
Selected Answer: A
The question is about cross-region snapshot copy (read carefully), not about cross-region replication, so B and D are out. From the remaining A and C, I would tend to A because the KMS key is needed from the source, the target only needs a grant on it.
upvoted 1 times
...
aqiao
1 year, 9 months ago
Selected Answer: C
Seek “Copying AWS KMS–encrypted snapshots to another AWS Region” from https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-db-encryption.html No need to create IAM role
upvoted 1 times
...
mraronsimon
1 year, 11 months ago
Selected Answer: C
"To copy snapshots for AWS KMS–encrypted clusters to another AWS Region, create a grant for Amazon Redshift to use a customer managed key in the destination AWS Region. Then choose that grant when you enable copying of snapshots in the source AWS Region." Reference: https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-snapshots.html
upvoted 1 times
...
adelcold
2 years ago
Selected Answer: D
https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-db-encryption.html#configure-snapshot-copy-grant
upvoted 1 times
...
adelcold
2 years ago
D is correct https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-db-encryption.html#configure-snapshot-copy-grant
upvoted 1 times
...
ken_test1234
2 years, 2 months ago
Selected Answer: C
because of this documentation https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-snapshots.html Copying snapshots to another AWS Region article shows c is the answer
upvoted 1 times
Mintwater
2 years, 2 months ago
Why is D not correct?
upvoted 1 times
Sathish_dbs
1 year, 8 months ago
because there is no cross region replication with redshift
upvoted 1 times
...
...
...
teo2157
2 years, 5 months ago
Selected Answer: C
The answer is explained here: https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-db-encryption.html#working-with-aws-kms, look for "copying AWS KMS–encrypted snapshots to another AWS Region"
upvoted 1 times
...
lollyj
2 years, 6 months ago
Selected Answer: D
I thought keys are region specific and one will need to be created in the destination region
upvoted 1 times
...
Dantas
3 years ago
Selected Answer: C
https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-db-encryption.html
upvoted 2 times
...
novice_expert
3 years, 1 month ago
Selected Answer: C
-A,B,D are incorrect -C new KMS in the destination Region -> snapshot copy grant in the destination Region specifying the new key ->In the source Region, configure cross-Region snapshots for the Amazon Redshift cluster specifying - the destination Region, - the snapshot copy grant, - and retention periods for the snapshot.
upvoted 1 times
...
victornj
3 years, 5 months ago
Question is poorly written . In absence of true answer C is right. It is right because A,B,D are not correct. You definitely need snapshot copy grant in destination region but based on that region key. Answer C does not say which key.
upvoted 3 times
user0001
3 years, 3 months ago
agree with you
upvoted 1 times
...
...
MahiShai
3 years, 5 months ago
C is correct ans
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...