Replicate Secrets Manager secrets across Regions with a multi-Region customer managed KMS key

Answer Correct answer: D — use a customer managed multi-Region KMS key replicated to us-west-1 so the secret and its key both exist in each Region.

A company runs workloads in the us-east-1 Region. The company has never deployed resources to other AWS Regions and does not have any multi-Region resources. The company needs to replicate its workloads and infrastructure to the us-west-1 Region. A security engineer must implement a solution that uses AWS Secrets Manager to store secrets in both Regions. The solution must use AWS Key Management Service (AWS KMS) to encrypt the secrets. The solution must minimize latency and must be able to work if only one Region is available. The security engineer uses Secrets Manager to create the secrets in us-east-1. What should the security engineer do next to meet the requirements?

  1. Encrypt the secrets in us-east-1 by using an AWS managed KMS key. Replicate the secrets to us-west-1. Encrypt the secrets in us-west-1 by using a new AWS managed KMS key in us-west-1.
  2. Encrypt the secrets in us-east-1 by using an AWS managed KMS key. Configure resources in us-west-1 to call the Secrets Manager endpoint in us-east-1.
  3. Encrypt the secrets in us-east-1 by using a customer managed KMS key. Configure resources in us-west-1 to call the Secrets Manager endpoint in us-east-1.
  4. Encrypt the secrets in us-east-1 by using a customer managed KMS key. Replicate the secrets to us-west-1. Encrypt the secrets in us-west-1 by using the customer managed KMS key from us-east-1. Correct Answer

Community Votes

D
60%
A
40%

60% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Secrets Manager secret replication requires a KMS key in the replica Region. Multi-Region customer managed KMS keys can be replicated so the same logical key exists in both Regions; AWS managed keys are always single-Region and therefore cannot back a replicated secret. Using one replicated CMK keeps decryption possible from either Region if the other is unavailable.

A company must replicate Secrets Manager secrets from us-east-1 to us-west-1, encrypted with KMS, working even if one Region is down and with low latency. Secrets Manager replica secrets must be encrypted with a KMS key present in the replica Region. AWS managed keys are single-Region and cannot be used as replica keys, so a customer managed multi-Region KMS key replicated to us-west-1 is required.

Choosing the AWS managed KMS key option, assuming managed keys replicate. They are single-Region by design, so a secret replicated to us-west-1 encrypted with an us-east-1 AWS managed key cannot be decrypted there, violating the single-Region-down requirement.

Community Discussion (7 comments)

TareDHakim 👍 1 Selected: D
the question doesn't specify the type of KMS key (aws managed or customer managed), since AWS managed KMS keys are region-specific, option A won't work for cross-region replication of secrets. The correct solution is Option D, which uses a customer managed KMS key that can be replicated across multiple regions, fulfilling the requirements of cross region replicas.
Asma2023 👍 1 Selected: A
AWS managed key is less complicated
SCSC02Q 👍 1 Selected: A
Since solution must work if a region is down.
koo_kai 👍 2 Selected: A
The question does not state that a multi-region key is used. KMS is usually a regional service. "must be able to work if only one Region is available"
dhewa 👍 1 Selected: D
By using a customer managed KMS key, you ensure that the same key is used for encryption in both Regions, maintaining consistency and security. Replicating the secrets ensures that they are available in both Regions, reducing latency and providing redundancy in case one Region becomes unavailable.
gkaself 👍 1 Selected: D
D is correct Answer
mikelord 👍 3 Selected: D
D should be the right answer.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Secrets Manager replica secrets must be encrypted with a KMS key that exists in the replica Region. A customer managed multi-Region KMS key can be replicated so the identical key material is available in both us-east-1 and us-west-1. Replicating the secret and encrypting it with that same replicated key means resources in either Region can decrypt locally, satisfying low latency and continued operation if one Region fails.

Why the Other Options Are Wrong

A is wrong because AWS managed KMS keys are single-Region and cannot be used as replica keys; the us-west-1 copy would need a different key, breaking the single-Region-down guarantee. B and C are wrong because having us-west-1 call the us-east-1 Secrets Manager endpoint introduces cross-Region latency and a hard dependency on us-east-1 being available, violating both stated requirements.

Community Comment Notes

Votes favored D over A. A key comment noted "AWS managed keys are always single-Region keys," so they cannot back a replica secret. D supporters emphasized that a single replicated CMK keeps access consistent if one Region is down; A supporters misunderstood managed keys as replicating.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide