Allow cross-account events into the DevOps event bus and create a rule in each account targeting that bus

Answer Correct answer: C — allow cross-account events into the DevOps event bus and create a rule in each account targeting that bus.

A company has several AWS accounts. An Amazon Connect instance runs in each account. The company uses an Amazon EventBridge default event bus in each account for event handling. A DevOps team needs to receive all the Amazon Connect events in a single DevOps account. Which solution meets these requirements?

  1. Update the resource-based policy of the default event bus in each account to allow the DevOps account to replay events. Configure an EventBridge rule in the DevOps account that matches Amazon Connect events and has a target of the default event bus in the other accounts.
  2. Update the resource-based policy of the default event bus in each account to allow the DevOps account to receive events. Configure an EventBridge rule in the DevOps account that matches Amazon Connect events and has a target of the default event bus in the other accounts.
  3. Update the resource-based policy of the default event bus in the DevOps account. Update the policy to allow events to be received from the accounts. Configure an EventBridge rule in each account that matches Amazon Connect events and has a target of the DevOps account's default event bus. Correct Answer
  4. Update the resource-based policy of the default event bus in the DevOps account. Update the policy to allow events to be replayed by the accounts. Configure an EventBridge rule in each account that matches Amazon Connect events and has a target of the DevOps account's default event bus.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The direction of the flow determines where the policy and the rule go. Because events travel from each account into the DevOps account, the resource-based policy that must be opened is the DevOps account's event bus, and the rules must be created in the source accounts with the DevOps bus as their target (C). Option C states exactly that. Options A and B invert both halves, trying to push events from the DevOps account out to the other accounts' buses, and they use replay semantics, which is a separate archival capability rather than live event delivery.

Each account has its own default event bus and the DevOps team needs all Amazon Connect events in one account. EventBridge rules can target another account's event bus, but the receiving bus must permit it. The resource-based policy of the DevOps account's default event bus is therefore updated to allow events from the other accounts to be received, and an EventBridge rule is created in each account that matches Amazon Connect events and targets the DevOps account's default event bus as its destination, so events flow directly from each account into the central bus.

Updating the resource-based policy of the default event bus in each source account to allow the DevOps account to replay or receive events, with a rule in the DevOps account targeting the other accounts' buses (A and B) — this reverses the direction of the flow, since rules deliver events from the account where the rule lives to its target, so a rule in the DevOps account would push DevOps events outward rather than collecting events from the other accounts. f4b18ba and Ky_24 both described the correct direction: the DevOps account's event bus needs the resource-based policy allowing events to be received from the other accounts. Describing the permission as allowing the DevOps account to replay events (A) also misstates the capability, since replay is the archival function of an event bus rather than live cross-account delivery.

Community Discussion (4 comments)

Srikantha 👍 1 Selected: C
Explanation: 1. Event Flow Across AWS Accounts The goal is to consolidate Amazon Connect events from multiple AWS accounts into a single DevOps account. Amazon EventBridge allows cross-account event ingestion using a resource-based policy on the receiving event bus (DevOps account). 2. Correct Configuration Steps ✅ Step 1: Update the resource-based policy of the default event bus in the DevOps account This allows it to receive events from other accounts. The policy must specify the source accounts and the events.amazonaws.com principal. ✅ Step 2: Create EventBridge rules in each Amazon Connect account These rules match Amazon Connect events and forward them to the DevOps account's default event bus.
teo2157 👍 2 Selected: C
Agree with f4b18ba comments
Ky_24 👍 3 Selected: C
Explanation: To centralize Amazon Connect events from multiple AWS accounts into a single account’s EventBridge event bus, the following steps are required: 1. Update the resource-based policy of the EventBridge event bus in the DevOps account: • This policy allows the DevOps account’s event bus to accept events from the other accounts. • The policy must specify the sending account IDs in the Principal field and grant permissions for actions like events:PutEvents. 2. Create EventBridge rules in each Amazon Connect account: • These rules match the specific Amazon Connect events (e.g., contact events, agent status updates) and forward them to the default event bus in the DevOps account.
f4b18ba 👍 3 Selected: C
Resource-Based Policy on the DevOps Account's Event Bus: To allow cross-account event routing, the DevOps account's EventBridge event bus must have a resource-based policy that grants permissions to other accounts to send events to it. EventBridge Rule in Each Account: Each account needs an EventBridge rule that matches the desired Amazon Connect events and sends them to the DevOps account's event bus as the target. This ensures all relevant events are aggregated in the DevOps account. Cross-Account Event Routing: EventBridge supports cross-account event routing with a combination of resource-based policies and properly configured rules in the source accounts. https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-cross-account.html https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-event-bus-permissions.html https://docs.aws.amazon.com/connect/latest/adminguide/eventbridge.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon EventBridge rules deliver events from the account in which the rule is defined to the target specified on the rule, and a target may be another account's event bus provided that receiving bus permits it. Since the requirement is to collect Amazon Connect events from several source accounts into a single DevOps account, the events must flow from each source account into the DevOps account's default event bus. Two changes accomplish this. First, the resource-based policy of the DevOps account's default event bus is updated so that the other accounts are allowed to put events into it (C). Second, an EventBridge rule is created in each account that matches Amazon Connect events and uses the DevOps account's default event bus as its target, so every matching event is delivered into the central bus (C). Both Ky_24 and f4b18ba described exactly this direction of flow, with f4b18ba noting that the DevOps account's event bus must have a resource-based policy granting the other accounts permission to deliver events into it. C is the correct answer.

Why the Other Options Are Wrong

A updates the resource-based policy of the default event bus in each account to allow the DevOps account to replay events, then configures an EventBridge rule in the DevOps account that matches Amazon Connect events and targets the default event bus in the other accounts. This reverses the required direction. A rule delivers events outward from the account where it is defined, so a rule in the DevOps account would push DevOps account events to the other accounts' buses rather than collecting events from those accounts into the DevOps account. In addition, describing the permission as allowing replay misidentifies the capability: replay is the archival function of an event bus, not live event delivery. B makes the same two errors, updating the source accounts' bus policies to allow the DevOps account to receive events and placing the rule in the DevOps account with the other accounts' buses as targets, so events still flow the wrong way. C is correct.

Community Comment Notes

Community voted C unanimously. Srikantha explained that the goal is to consolidate Amazon Connect events from multiple accounts into a single DevOps account using EventBridge cross-account event ingestion, matching option C's structure. Ky_24 described the required steps precisely as updating the resource-based policy of the DevOps account's default event bus to allow events from the other accounts and creating a rule in each account targeting that bus. f4b18ba confirmed the same reasoning about the resource-based policy on the DevOps account's bus granting the other accounts permission. teo2157 agreed. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide