Allow the primary account in the destination vault access policy and share the primary KMS key with the destination account
A company uses an organization in AWS Organizations that has all features enabled. The company uses AWS Backup in a primary account and uses an AWS Key Management Service (AWS KMS) key to encrypt the backups. The company needs to automate a cross-account backup of the resources that AWS Backup backs up in the primary account. The company configures cross-account backup in the Organizations management account. The company creates a new AWS account in the organization and configures an AWS Backup backup vault in the new account. The company creates a KMS key in the new account to encrypt the backups. Finally, the company configures a new backup plan in the primary account. The destination for the new backup plan is the backup vault in the new account. When the AWS Backup job in the primary account is invoked, the job creates backups in the primary account. However, the backups are not copied to the new account's backup vault. Which combination of steps must the company take so that backups can be copied to the new account's backup vault? (Choose two.)
Community Votes
75% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Cross-account backup requires authorization in two places in the destination account: the destination backup vault's access policy must allow the primary account (A), and the primary account's KMS key policy must be shared with the new account (D) so the backup job can encrypt the copied backups. Editing the source vault's access policy or the destination key's key policy is not what enables the copy; the vault that receives the backups is the one whose access policy matters, and the key used to encrypt them is the destination key whose policy must permit the primary account.
AWS Backup cross-account backup requires two things in the destination account: a backup vault whose access policy permits the source account, and a customer managed KMS key whose key policy is shared with the source account so the primary account's backup job can encrypt into the destination vault. Because the destination vault already exists with its own KMS key, the primary account's vault access policy and the primary account's key policy must both be edited so the backup service in the primary account is authorized to write into the destination vault.
Editing the backup vault access policy in the primary account (B and C) — the primary account's vault is not the destination for the copied backups, so changing its access policy has no effect on whether the new account's vault accepts the copy. Editing the key policy of the KMS key in the new account to share it with the primary account (E) — the backups copied into the new account's vault are encrypted with the destination key, and it is the source account's key policy that must permit the destination account for the copy to be encrypted and written. luisfsm_111 argued D is unnecessary because the new account uses its own key, but the cross-account backup documentation requires the source key policy to allow the destination account.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS Backup cross-account backup works by having the backup job in the primary account write backup copies into a backup vault owned by the destination account. For that to succeed, the destination account's backup vault access policy must allow the primary account to put backups into it (A). In addition, the customer managed KMS key used to encrypt those backups must permit the destination account to use it, which means the key policy of the KMS key in the primary account has to be shared with the new account (D). The AWS cross-account backup documentation describes exactly these two required policy edits in the destination account's setup: the vault access policy allowing the source account, and the key policy sharing the key with the destination account.Why the Other Options Are Wrong
B edits the backup vault access policy in the primary account. The primary account's vault is not the target of the cross-account copy, so permitting the new account there does not enable the copy into the new account's vault. C edits the primary account's vault access policy to allow the KMS key in the new account, which conflates the vault access policy with the key policy; these are separate resources with separate authorization semantics. E edits the key policy of the KMS key in the new account to share it with the primary account. Because the backups written into the new account's vault are encrypted with the destination key, it is the source account's key policy that must allow the destination account; sharing the destination key alone does not authorize the primary account's backup job. A and D are the correct combination.Community Comment Notes
Community voted A,D (75), with A,E a 25 percent minority. auxwww and xdkonorek2 both cited the AWS cross-account backup documentation, noting that in the destination account you must create a backup vault, assign a customer managed key to encrypt backups, and add a resource-based access policy allowing the source account. luisfsm_111 argued D is unnecessary since the destination uses its own key, but the documented flow requires the source key policy to permit the destination account.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →