A company uses AWS Organizations. The company has learned to use an AWS CloudHSM hardware security module (HSM) that is hosted in a central AWS account. One team creates its own dedicated AWS account and wants to use the HSM hosted in the central account.
How should a security engineer share the HSM hosted in the central account with the new dedicated account?
A Use AWS Resource Access Manager (AWS RAM) to share the VPC subnet ID of the HSM that is hosted in the central account with the new dedicated account. Configure the CloudHSM security group to accept inbound traffic from the private IP addresses of client instances in the new dedicated account. B Use AWS Identity and Access Management (IAM) to create a cross-account role to access the CloudHSM cluster that is in the central account. Create a new IAM user in the new dedicated account. Assign the cross-account role to the new IAM user. C Use AWS IAM Identity Center to create an AWS Security Token Service (AWS STS) token to authenticate from the new dedicated account to the central account. Use the cross-account permissions that are assigned to the STS token to invoke an operation on the HSM in the central account. D Use AWS Resource Access Manager (AWS RAM) to share the ID of the HSM that is hosted in the central account with the new dedicated account. Configure the CloudHSM security group to accept inbound traffic from the private IP addresses of client instances in the now dedicated account. Show Answer Answer Explanation AWS RAM can share VPC subnets with accounts in the same AWS Organization, allowing the dedicated account to place CloudHSM client instances in the centrally managed VPC. The CloudHSM security group must also permit traffic from those client instances so they can connect to the HSM network interfaces. AWS RAM supports sharing the subnet, not an HSM ID; IAM and STS permissions alone do not establish CloudHSM client-to-HSM network access.
Learn more
Community Discussion