Use a KMS multi-Region key so one key material encrypts in every Region

Answer Correct answer: A — Create a KMS multi-Region primary key and its replica key in each additional Region, then point the application code at the local replica key.

A company has an application that uses AWS Key Management Service (AWS KMS) to encrypt and decrypt data. The application stores data in an Amazon S3 bucket in an AWS Region. Company security policies require the data to be encrypted before the data is placed into the S3 bucket. The application must decrypt the data when the application reads files from the S3 bucket. The company replicates the S3 bucket to other Regions. A solutions architect must design a solution so that the application can encrypt and decrypt data across Regions. The application must use the same key to decrypt the data in each Region. Which solution will meet these requirements?

  1. Create a KMS multi-Region primary key. Use the KMS multi-Region primary key to create a KMS multi-Region replica key in each additional Region where the application is running. Update the application code to use the specific replica key in each Region. Correct Answer
  2. Create a new customer managed KMS key in each additional Region where the application is running. Update the application code to use the specific KMS key in each Region.
  3. Use AWS Private Certificate Authority to create a new certificate authority (CA) in the primary Region. Issue a new private certificate from the CA for the application’s website URL. Share the CA with the additional Regions by using AWS Resource Access Manager (AWS RAM). Update the application code to use the shared CA certificates in each Region.
  4. Use AWS Systems Manager Parameter Store to create a parameter in each additional Region where the application is running. Export the key material from the KMS key in the primary Region. Store the key material in the parameter in each Region. Update the application code to use the key data from the parameter in each Region.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A KMS multi-Region primary key has the same key material in every Region where its replica keys exist, so a ciphertext produced in one Region is decryptable in the others with the same logical key rather than a per-Region key.

An application uses AWS KMS to encrypt data before writing it to an S3 bucket, and the bucket is replicated to other Regions. The application must decrypt the replicated data in each Region using the same key, which means the key itself has to be usable in every Region.

Creating an unrelated customer managed key per Region. Each key has different key material, so a ciphertext encrypted in one Region cannot be decrypted with the key in another, and the company would have to re-encrypt the data during replication rather than decrypting it as required.

Community Discussion (5 comments)

ebbff63 👍 11 Selected: A
A- straightforward - encryption and decryption across regions using multi-region key
AzureDP900 👍 1
A) Create a KMS multi-Region primary key. Use the KMS multi-Region primary key to create a KMS multi-Region replica key in each additional Region where the application is running. Update the application code to use the specific replica key in each Region. To meet the requirements, you need to use the same key to decrypt data across Regions, while also using AWS Key Management Service (KMS) to manage encryption and decryption.
AzureDP900 👍 1
Option A Creating a KMS multi-region primary key allows you to manage encryption keys across multiple Regions. A KMS multi-region primary key can be used to create a KMS multi-region replica key, which can then be used to encrypt and decrypt data in other Regions. The application code can be updated to use the specific replica key in each Region, ensuring that the same key is used for encryption and decryption across all Regions. The other options do not meet all of the requirements:
backbencher2022 👍 1 Selected: A
A is the correct answer as per this AWS documentation - https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.html#:~:text=A%20multi%2DRegion%20primary%20key%20is%20a%20KMS%20key%20that,primary%20key%20can%20be%20replicated.
AhmedSalem 👍 1 Selected: A
Answer A. AWS KMS multi-Region keys allow you to replicate keys across multiple Regions, ensuring that the same key material is available in each Region.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A KMS multi-Region primary key is designed for exactly this scenario. The primary key and its replica keys in other Regions share the same key material, so data encrypted under the primary key in one Region can be decrypted under the corresponding replica key in any other Region. The application therefore uses one logical key across the fleet, and when S3 replication copies objects to another Region the application can decrypt them with the replica key in that Region. The keys are linked so that rotation and revocation behaviour is managed as a set rather than per Region, which keeps the operational surface small.

Why the Other Options Are Wrong

B: Separate customer managed keys in each Region have entirely different key material, so a ciphertext created under the primary Region key cannot be decrypted with the key in another Region. The company would have to re-encrypt the data before it could be read elsewhere, which contradicts the requirement to use the same key to decrypt in each Region. C: AWS Private Certificate Authority issues X.509 certificates for TLS or code signing, it does not provide symmetric data encryption keys, so it has no role in encrypting S3 object content. D: Storing exported key material in Systems Manager Parameter Store in each Region means copying sensitive key bytes into a parameter in every Region, which duplicates the secret and expands the exposure surface, and Parameters do not provide the cryptographic operations the application needs from KMS.

Community Comment Notes

The community voted 100 to 0 for A, and the top-voted comment characterised it as the straightforward answer, encryption and decryption across Regions using a multi-Region key. Another linked the AWS KMS multi-Region keys overview documentation and quoted it directly on a multi-Region primary key, and a further commenter noted that multi-Region keys replicate the same key material so the same key is available in each Region.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide