Cross-Account QuickSight Access to S3 with KMS
A company uses Amazon S3 to store data and Amazon QuickSight to create visualizations, The company has an S3 bucket in an AWS account named Hub-Account. The S3 bucket is encrypted by an AWS Key Management Service (AWS KMS) key. The company's QuickSight instance is in a separate account named BI-Account. The company updates the S3 bucket policy to grant access to the QuickSight service role. The company wants to enable cross-account access to allow QuickSight to interact with the S3 bucket. Which combination of steps will meet this requirement? (Choose two.)
Community Votes
67% of anonymous learners picked answer E. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core concept tested is that cross-account access to encrypted data requires explicit permissions on both the storage resource (S3) and the encryption key (KMS). The common trap is ignoring the KMS decryption requirement or duplicating S3 permissions.
This question examines the necessary IAM and KMS configurations for cross-account access between Amazon QuickSight and an encrypted Amazon S3 bucket. It establishes that granting S3 access alone is insufficient when encryption keys are involved.
Many learners choose B and D, believing they need to add the S3 bucket to the role's resources. However, since the question states the S3 bucket policy is already updated to grant access, adding it again is redundant. Others miss the KMS requirement entirely.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct combination is D and E. The scenario specifies that the S3 bucket policy has already been updated to grant access to the QuickSight service role, which effectively addresses the S3 data plane access (making option B redundant). However, because the data is encrypted with a customer-managed AWS KMS key, QuickSight must also have permission to decrypt the data. This requires two additional steps: adding the KMS key to the QuickSight service role's IAM policy (Option D) to allowkms:Decrypt actions, and ensuring the KMS key policy grants access to the QuickSight service role (Option E). Without these, QuickSight cannot read the encrypted objects.Why the Other Options Are Wrong
Option A is incorrect because AWS KMS does not encrypt the connection; it encrypts the data at rest. Option C is incorrect because AWS RAM is used for sharing specific resources like Transit Gateways or Database instances, but S3 buckets are shared via bucket policies, not RAM. Option B is incorrect because the question explicitly states the S3 bucket policy is already updated, so this step is already done.Community Comment Notes
Several community members correctly identified the need for both IAM and Key Policy changes. As devan007 noted, "D & E S3 bucket policy is already updated from the question." Others like YUICH emphasized that the existing policy handles S3 access, leaving only the KMS configuration as the remaining hurdle. Comments consistently pointed out that without KMS permissions, the S3 access would fail due to encryption errors.Official Reference
Exam Strategy
Always check if a prerequisite step mentioned in the question stem has already been completed by the user. If the S3 bucket policy is already set, you do not need to select an option that sets it again. Focus on the missing pieces—in this case, the encryption key permissions.
Frequently Asked Questions
Why is Option B incorrect if we need cross-account S3 access?
The question states the S3 bucket policy is already updated to grant access. Option B suggests adding the bucket to the role's resources, which is redundant or refers to a different mechanism than the bucket policy already applied.
Do I need to update both IAM and KMS policies for cross-account KMS access?
Yes. The IAM policy allows the role to request the action (e.g., kms:Decrypt), while the KMS key policy must authorize that specific principal to perform the action on the key.
Related Analysis
Practice All DEA-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DEA-C01 Practice Test →