Question 1 · choose 3
An application role in account A must read objects from a bucket in account B without assuming any role in account B. The objects are encrypted with SSE-KMS using a customer managed key in account B. Which changes are required? (Choose THREE.)
- AAn SCP on account B that allows s3:GetObject for principals in account A
- BAn identity policy on the role that allows s3:GetObject and kms:Decrypt
- CA bucket policy in account B that allows the role to call s3:GetObject
- DTurn off the S3 Block Public Access settings for the bucket in account B
- EA key policy statement in account B that allows the role kms:Decrypt
- FChange the bucket's default encryption from SSE-KMS to SSE-S3
Show the answer and why
AAn SCP on account B that allows s3:GetObject for principals in account A
Incorrect
SCPs never grant permissions; they only limit principals in member accounts.
BAn identity policy on the role that allows s3:GetObject and kms:Decrypt
Correct
For cross-account access, the caller's own account must also allow the actions, for S3 and for the key.
CA bucket policy in account B that allows the role to call s3:GetObject
Correct
The bucket owner must grant the other account's principal access in a resource-based policy.
DTurn off the S3 Block Public Access settings for the bucket in account B
Incorrect
A bucket policy that grants a fixed principal is not public, so Block Public Access does not need to change.
EA key policy statement in account B that allows the role kms:Decrypt
Correct
Cross-account use of a KMS key needs permission in the key policy and in an IAM policy in the external account; neither is enough alone.
FChange the bucket's default encryption from SSE-KMS to SSE-S3
Incorrect
Default encryption applies to new objects. The existing objects stay encrypted with the KMS key.
Cross-account access needs an allow on both sides: the caller's identity policy and the resource owner's policy, and with SSE-KMS the key policy is a second resource owner to satisfy.
AWS documentation
- Bucket owner granting cross-account bucket permissions (opens in a new tab)
- Allowing users in other accounts to use a KMS key (opens in a new tab)
- Service control policies (SCPs) (opens in a new tab)
- Blocking public access to your Amazon S3 storage (opens in a new tab)
- Setting default server-side encryption behavior for Amazon S3 buckets (opens in a new tab)