QuestionQ18

Security and Compliance

A CloudOps engineer needs to share a copy of a production database with a migration account. The production database runs on an Amazon RDS DB instance and is encrypted at rest using an AWS Key Management Service (AWS KMS) key with the alias production-rds-key.

What must the CloudOps engineer do to satisfy these requirements with the LEAST administrative overhead?

Explanation

An encrypted Amazon RDS snapshot can be shared cross-account when it is encrypted with a customer managed KMS key and that key’s policy allows the target account to use it. Granting the migration account access to production-rds-key and sharing a manual snapshot uses the native RDS cross-account snapshot workflow. An identical KMS alias in the target account does not provide access to the source key, and export/import introduces unnecessary operational work.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!