QuestionQ8

Data Protection

A company operates workloads in the us-east-1 Region. The company has never deployed resources in any other AWS Region and has no multi-Region resources. The company must replicate its workloads and infrastructure to the us-west-1 Region.

A security engineer must implement a solution that uses AWS Secrets Manager to store secrets in both Regions. The solution must use AWS Key Management Service (AWS KMS) to encrypt the secrets, minimize latency, and continue to work when only one Region is available.

The security engineer creates the secrets in us-east-1 by using Secrets Manager.

What should the security engineer do next to meet these requirements?

Explanation

Secrets Manager secret replication creates a replica in the target Region, allowing local access for low latency and continued use if the other Region is unavailable. Each regional secret can be encrypted with that Region’s AWS managed aws/secretsmanager KMS key. AWS managed KMS keys are regional, so a key in us-east-1 cannot be used directly to encrypt a secret replica in us-west-1.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!