Cross-Account QuickSight Access to S3 with KMS

Answer Correct answer: D, E — Add an IAM policy to the QuickSight service role to give QuickSight access to the KMS key that encrypts the S3 bucket, and add the KMS key as a resource that the QuickSight service role can access.

A company uses Amazon S3 to store data and Amazon QuickSight to create visualizations, The company has an S3 bucket in an AWS account named Hub-Account. The S3 bucket is encrypted by an AWS Key Management Service (AWS KMS) key. The company's QuickSight instance is in a separate account named BI-Account. The company updates the S3 bucket policy to grant access to the QuickSight service role. The company wants to enable cross-account access to allow QuickSight to interact with the S3 bucket. Which combination of steps will meet this requirement? (Choose two.)

  1. Use the existing AWS KMS key to encrypt connections from QuickSight to the S3 bucket.
  2. Add the S3 bucket as a resource that the QuickSight service role can access.
  3. Use AWS Resource Access Manager (AWS RAM) to share the S3 bucket with the BI-Account account.
  4. Add an IAM policy to the QuickSight service role to give QuickSight access to the KMS key that encrypts the S3 bucket. Correct Answer
  5. Add the KMS key as a resource that the QuickSight service role can access. Correct Answer

Community Votes

E
67%
B
33%

67% of anonymous learners picked answer E. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core concept tested is that cross-account access to encrypted data requires explicit permissions on both the storage resource (S3) and the encryption key (KMS). The common trap is ignoring the KMS decryption requirement or duplicating S3 permissions.

This question examines the necessary IAM and KMS configurations for cross-account access between Amazon QuickSight and an encrypted Amazon S3 bucket. It establishes that granting S3 access alone is insufficient when encryption keys are involved.

Many learners choose B and D, believing they need to add the S3 bucket to the role's resources. However, since the question states the S3 bucket policy is already updated to grant access, adding it again is redundant. Others miss the KMS requirement entirely.

Community Discussion (13 comments)

Ell89 👍 1 Selected: E
B & E. the issue isnt with sharing the bucket as the bucket policy does that already to the service role. its an encryption issue.
fnuuu 👍 1 Selected: B
BD : B - To ensure QS has permissions to access the S3 D - To ensure QS has permission for KMS to decrypt date in S3
YUICH 👍 1 Selected: B
BD Conclusion: To enable cross-account access for both (1) the Amazon S3 bucket and (2) the KMS key used to encrypt that bucket, the QuickSight service role must be granted the appropriate permissions. Among the provided options, the following two steps are essential: B. Add the S3 bucket as a resource the QuickSight service role can access (→ Allows cross-account access to the S3 bucket) D. Add an IAM policy to the QuickSight service role that grants access to the KMS key (→ Allows decryption of data encrypted by the KMS key)
stevejake 👍 1 Selected: D
S3 bucket policy is already updated from the question. Hence KMS key policy and IAM policy need to be altered to allow QuickSight service account to access KMS key.
YUICH 👍 1 Selected: B
Given that the question states “Update the S3 bucket policy to allow access for the QuickSight service role” and, from the perspective of “enabling cross-account access so that QuickSight can interact with the S3 bucket,” is asking what additional steps are needed, we can conclude that: (B) “Add the S3 bucket as a resource accessible by the QuickSight service role” (E) “Add the KMS key as a resource accessible by the QuickSight service role” together most succinctly represent the final actions required.
devan007 👍 4 Selected: E
D & E S3 bucket policy is already updated from the question. Hence KMS key policy and IAM policy need to be altered to allow QuickSight service account to access KMS key.
michele_scar 👍 1 Selected: E
B for bucket access E for KMS key policy
Eleftheriia 👍 2
It is BD
kupo777 👍 3
Correct Answer: DE
truongnguyen86 👍 3
Answer BE: Step to enable cross-account access: 1. update S3 bucket policy in Hub-account (B) 2. Update the KMS key Policy in Hub-Account(E) 3. Config QuickSight to access S3
pikuantne 👍 3
Answer: BD
2022MMTT 👍 4
Answer : DE
Parandhaman_Margan 👍 1
Answer:BE

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct combination is D and E. The scenario specifies that the S3 bucket policy has already been updated to grant access to the QuickSight service role, which effectively addresses the S3 data plane access (making option B redundant). However, because the data is encrypted with a customer-managed AWS KMS key, QuickSight must also have permission to decrypt the data. This requires two additional steps: adding the KMS key to the QuickSight service role's IAM policy (Option D) to allow kms:Decrypt actions, and ensuring the KMS key policy grants access to the QuickSight service role (Option E). Without these, QuickSight cannot read the encrypted objects.

Why the Other Options Are Wrong

Option A is incorrect because AWS KMS does not encrypt the connection; it encrypts the data at rest. Option C is incorrect because AWS RAM is used for sharing specific resources like Transit Gateways or Database instances, but S3 buckets are shared via bucket policies, not RAM. Option B is incorrect because the question explicitly states the S3 bucket policy is already updated, so this step is already done.

Community Comment Notes

Several community members correctly identified the need for both IAM and Key Policy changes. As devan007 noted, "D & E S3 bucket policy is already updated from the question." Others like YUICH emphasized that the existing policy handles S3 access, leaving only the KMS configuration as the remaining hurdle. Comments consistently pointed out that without KMS permissions, the S3 access would fail due to encryption errors.

Official Reference

Exam Strategy

Always check if a prerequisite step mentioned in the question stem has already been completed by the user. If the S3 bucket policy is already set, you do not need to select an option that sets it again. Focus on the missing pieces—in this case, the encryption key permissions.

Frequently Asked Questions

Why is Option B incorrect if we need cross-account S3 access?

The question states the S3 bucket policy is already updated to grant access. Option B suggests adding the bucket to the role's resources, which is redundant or refers to a different mechanism than the bucket policy already applied.

Do I need to update both IAM and KMS policies for cross-account KMS access?

Yes. The IAM policy allows the role to request the action (e.g., kms:Decrypt), while the KMS key policy must authorize that specific principal to perform the action on the key.

More DEA-C01 FAQ →

Related Analysis

Practice All DEA-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DEA-C01 Practice Test →

← Back to DEA-C01 Study Guide