Allow cross-account events into the DevOps event bus and create a rule in each account targeting that bus
A company has several AWS accounts. An Amazon Connect instance runs in each account. The company uses an Amazon EventBridge default event bus in each account for event handling. A DevOps team needs to receive all the Amazon Connect events in a single DevOps account. Which solution meets these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The direction of the flow determines where the policy and the rule go. Because events travel from each account into the DevOps account, the resource-based policy that must be opened is the DevOps account's event bus, and the rules must be created in the source accounts with the DevOps bus as their target (C). Option C states exactly that. Options A and B invert both halves, trying to push events from the DevOps account out to the other accounts' buses, and they use replay semantics, which is a separate archival capability rather than live event delivery.
Each account has its own default event bus and the DevOps team needs all Amazon Connect events in one account. EventBridge rules can target another account's event bus, but the receiving bus must permit it. The resource-based policy of the DevOps account's default event bus is therefore updated to allow events from the other accounts to be received, and an EventBridge rule is created in each account that matches Amazon Connect events and targets the DevOps account's default event bus as its destination, so events flow directly from each account into the central bus.
Updating the resource-based policy of the default event bus in each source account to allow the DevOps account to replay or receive events, with a rule in the DevOps account targeting the other accounts' buses (A and B) — this reverses the direction of the flow, since rules deliver events from the account where the rule lives to its target, so a rule in the DevOps account would push DevOps events outward rather than collecting events from the other accounts. f4b18ba and Ky_24 both described the correct direction: the DevOps account's event bus needs the resource-based policy allowing events to be received from the other accounts. Describing the permission as allowing the DevOps account to replay events (A) also misstates the capability, since replay is the archival function of an event bus rather than live cross-account delivery.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Amazon EventBridge rules deliver events from the account in which the rule is defined to the target specified on the rule, and a target may be another account's event bus provided that receiving bus permits it. Since the requirement is to collect Amazon Connect events from several source accounts into a single DevOps account, the events must flow from each source account into the DevOps account's default event bus. Two changes accomplish this. First, the resource-based policy of the DevOps account's default event bus is updated so that the other accounts are allowed to put events into it (C). Second, an EventBridge rule is created in each account that matches Amazon Connect events and uses the DevOps account's default event bus as its target, so every matching event is delivered into the central bus (C). Both Ky_24 and f4b18ba described exactly this direction of flow, with f4b18ba noting that the DevOps account's event bus must have a resource-based policy granting the other accounts permission to deliver events into it. C is the correct answer.Why the Other Options Are Wrong
A updates the resource-based policy of the default event bus in each account to allow the DevOps account to replay events, then configures an EventBridge rule in the DevOps account that matches Amazon Connect events and targets the default event bus in the other accounts. This reverses the required direction. A rule delivers events outward from the account where it is defined, so a rule in the DevOps account would push DevOps account events to the other accounts' buses rather than collecting events from those accounts into the DevOps account. In addition, describing the permission as allowing replay misidentifies the capability: replay is the archival function of an event bus, not live event delivery. B makes the same two errors, updating the source accounts' bus policies to allow the DevOps account to receive events and placing the rule in the DevOps account with the other accounts' buses as targets, so events still flow the wrong way. C is correct.Community Comment Notes
Community voted C unanimously. Srikantha explained that the goal is to consolidate Amazon Connect events from multiple accounts into a single DevOps account using EventBridge cross-account event ingestion, matching option C's structure. Ky_24 described the required steps precisely as updating the resource-based policy of the DevOps account's default event bus to allow events from the other accounts and creating a rule in each account targeting that bus. f4b18ba confirmed the same reasoning about the resource-based policy on the DevOps account's bus granting the other accounts permission. teo2157 agreed. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →