Replicate Secrets Manager secrets across Regions with a multi-Region customer managed KMS key

Answer Correct answer: D — use a customer managed multi-Region KMS key replicated to us-west-1 so the secret and its key both exist in each Region.

A company runs workloads in the us-east-1 Region. The company has never deployed resources to other AWS Regions and does not have any multi-Region resources. The company needs to replicate its workloads and infrastructure to the us-west-1 Region. A security engineer must implement a solution that uses AWS Secrets Manager to store secrets in both Regions. The solution must use AWS Key Management Service (AWS KMS) to encrypt the secrets. The solution must minimize latency and must be able to work if only one Region is available. The security engineer uses Secrets Manager to create the secrets in us-east-1. What should the security engineer do next to meet the requirements?

  1. Encrypt the secrets in us-east-1 by using an AWS managed KMS key. Replicate the secrets to us-west-1. Encrypt the secrets in us-west-1 by using a new AWS managed KMS key in us-west-1.
  2. Encrypt the secrets in us-east-1 by using an AWS managed KMS key. Configure resources in us-west-1 to call the Secrets Manager endpoint in us-east-1.
  3. Encrypt the secrets in us-east-1 by using a customer managed KMS key. Configure resources in us-west-1 to call the Secrets Manager endpoint in us-east-1.
  4. Encrypt the secrets in us-east-1 by using a customer managed KMS key. Replicate the secrets to us-west-1. Encrypt the secrets in us-west-1 by using the customer managed KMS key from us-east-1. Correct Answer

Community Votes

D
56%
A
44%

56% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Secrets Manager secret replication requires a KMS key in the replica Region. Multi-Region customer managed KMS keys can be replicated so the same logical key exists in both Regions; AWS managed keys are always single-Region and therefore cannot back a replicated secret. Using one replicated CMK keeps decryption possible from either Region if the other is unavailable.

A company must replicate Secrets Manager secrets from us-east-1 to us-west-1, encrypted with KMS, working even if one Region is down and with low latency. Secrets Manager replica secrets must be encrypted with a KMS key present in the replica Region. AWS managed keys are single-Region and cannot be used as replica keys, so a customer managed multi-Region KMS key replicated to us-west-1 is required.

Choosing the AWS managed KMS key option, assuming managed keys replicate. They are single-Region by design, so a secret replicated to us-west-1 encrypted with an us-east-1 AWS managed key cannot be decrypted there, violating the single-Region-down requirement.

Community Discussion (15 comments)

5409b91 👍 9 Selected: D
D. Encrypt the secrets in us-east-1 by using a customer managed KMS key. Replicate the secrets to us-west-1. Encrypt the secrets in us-west-1 by using the customer managed KMS key from us-east-1. Customer Managed KMS Key: Encrypting secrets in us-east-1 with a customer managed KMS key allows greater control over key rotation policies and permissions, ensuring higher security and compliance. Replication of secrets to us-west-1: Replicating the secrets to us-west-1 ensures that the secrets are available in both regions, meeting the requirement to function even if only one region is available. Using the same customer managed KMS key in us-west-1: Encrypting the secrets in us-west-1 using the KMS key from us-east-1 ensures consistency in encryption and secret management across regions. Additionally, this can help minimize latency, as the same key is used for both regions, making the replication process more efficient.
AWSLoverLoverLoverLoverLover 👍 1 Selected: D
D. Encrypt the secrets in us-east-1 by using a customer managed KMS key. Replicate the secrets to us-west-1. Encrypt the secrets in us-west-1 by using the customer managed KMS key from us-east-1. A. is incorrect Using AWS-managed KMS keys for encryption would not allow you to have control over the keys across regions. Secrets in us-west-1 would use a different key, which could complicate key management and does not fulfill the requirement of using the same encryption key for replication.
Wardove 👍 1 Selected: A
Right answer is A as this the only technically possible option which fulfills the requirement. "For Encryption key, choose a KMS key to encrypt the secret with. The key must be in the replica Region." https://docs.aws.amazon.com/secretsmanager/latest/userguide/replicate-secrets.html
m_ch333 👍 1 Selected: D
Not A& B. AWS managed keys, the KMS keys that AWS services create in your account for you, are always single-Region keys. https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.html
saggys 👍 1 Selected: A
KMS key must be in the replica region.
klumzy 👍 1
A . KMS has regional service.
jamesf 👍 1 Selected: D
I go for D Not option A because separate keys, "Encrypt the secrets in us-west-1 by using a new AWS managed KMS key in us-west-1"
FunkyFresco 👍 1 Selected: A
Option A is the right one.
HunkyBunky 👍 1 Selected: A
I guess A - becuase solution must work even if us-east-1 will-be unavaliable, so we must use encryption key from us-west-1 too
Arad 👍 4 Selected: A
A is correct, the key point is availability is case one region is down.
cumzle_com 👍 2 Selected: D
Secrets are replicated to both regions, minimizing latency and ensuring availability. Using the same KMS key ensures consistent access control and simplifies management.
aescudero51 👍 1 Selected: B
My answer is B Encrypt the secrets in us-east-1 by using an AWS managed KMS key: Create an AWS managed KMS key in the us-east-1 Region. This key will be used to encrypt the secrets in both Regions. Use this key to encrypt the secrets in us-east-1. Replicate the secrets to us-west-1: Use the AWS Secrets Manager to replicate the encrypted secrets from us-east-1 to us-west-1. This ensures that the same secrets are available in both Regions. Configure resources in us-west-1 to call the Secrets Manager endpoint in us-east-1: Configure resources in us-west-1 to call the Secrets Manager endpoint in us-east-1 to retrieve the encrypted secrets. This allows the resources in us-west-1 to access the secrets without having to replicate the secrets to us-west-1.
grekh001 👍 2
A. "The solution must minimize latency and must be able to work if only one Region is available." A is the only solution that can work if one region is down.
Certified101 👍 3 Selected: A
A is correct
Nash101 👍 2
D A. Separate KMS Keys: Using separate managed KMS keys per Region creates a dependency on both Regions being available for decryption. If only one Region is accessible, the other Region's key wouldn't be usable. B & C. Secrets Manager Endpoint in us-east-1: These options rely on resources in us-west-1 calling the Secrets Manager endpoint in us-east-1. This introduces a single point of failure in us-east-1 and wouldn't achieve the desired redundancy and availability if us-east-1 becomes unavailable

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Secrets Manager replica secrets must be encrypted with a KMS key that exists in the replica Region. A customer managed multi-Region KMS key can be replicated so the identical key material is available in both us-east-1 and us-west-1. Replicating the secret and encrypting it with that same replicated key means resources in either Region can decrypt locally, satisfying low latency and continued operation if one Region fails.

Why the Other Options Are Wrong

A is wrong because AWS managed KMS keys are single-Region and cannot be used as replica keys; the us-west-1 copy would need a different key, breaking the single-Region-down guarantee. B and C are wrong because having us-west-1 call the us-east-1 Secrets Manager endpoint introduces cross-Region latency and a hard dependency on us-east-1 being available, violating both stated requirements.

Community Comment Notes

Votes favored D over A. A key comment noted "AWS managed keys are always single-Region keys," so they cannot back a replica secret. D supporters emphasized that a single replicated CMK keeps access consistent if one Region is down; A supporters misunderstood managed keys as replicating.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide