Question 1 · choose 1
A company runs AWS CodePipeline in a central tooling account. A new stage must run an AWS CloudFormation deploy action in a production account by assuming a role in that account. The first run fails because the production role cannot use the input artifact from the pipeline's S3 artifact bucket, which the console wizard created with its default encryption. The security team requires the artifacts to stay encrypted with AWS KMS. What should the DevOps engineer do?
- ACreate a customer managed KMS key in the pipeline's Region that the production account may use, make it the artifact store key, and grant the production role access to the bucket
- BKeep the default AWS managed key and add a bucket policy statement that grants the production account's deploy role s3:GetObject on every object in the artifact bucket
- CRemove default encryption from the artifact bucket and add a bucket policy that denies every request that does not use TLS
- DCreate a customer managed KMS key in the production account and reference it by its alias in the pipeline's artifact store settings
Show the answer and why
ACreate a customer managed KMS key in the pipeline's Region that the production account may use, make it the artifact store key, and grant the production role access to the bucket
Correct
This is the documented setup for cross-account actions: a customer managed key in the pipeline Region that the other account may use, the pipeline edited to use that key, and a bucket policy that gives the other account access to the artifact bucket.
BKeep the default AWS managed key and add a bucket policy statement that grants the production account's deploy role s3:GetObject on every object in the artifact bucket
Incorrect
The default AWS managed key cannot be changed, so the production account still could not decrypt the artifacts. Cross-account actions need a customer managed key that grants the other account.
CRemove default encryption from the artifact bucket and add a bucket policy that denies every request that does not use TLS
Incorrect
This drops encryption at rest with AWS KMS, which the security team requires. Requiring TLS protects data in transit only.
DCreate a customer managed KMS key in the production account and reference it by its alias in the pipeline's artifact store settings
Incorrect
An alias is recognized only in the account that created the key. For cross-account actions the key must be given by key ID or key ARN, and the documented setup creates the key in the pipeline's account and Region.
A cross-account action reads artifacts that the pipeline account wrote, so the other account needs both the bucket and the key. Only a customer managed key can grant another account; then the pipeline is switched to that key and the bucket policy and the assumed role give the access.
AWS documentation