Cross-Account Encryption Quiz

5 questions Pass: 70% +25 pts

Quiz covering Encryption

Cross-Account Encryption Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    When sharing an encrypted object across AWS accounts using AWS KMS, what is the most fundamental requirement to ensure the receiving account can decrypt the data?

  2. 2

    You are attempting to share an S3 bucket encrypted with a Customer Managed Key (CMK) with a different account. You have updated the Key Policy, but the other account still cannot access the files. What is the most likely missing step?

  3. 3

    Why is it generally considered a security best practice to use Customer Managed Keys (CMKs) instead of AWS Managed Keys when sharing resources across accounts?

  4. 4

    Which of the following describes the correct policy evaluation logic when a cross-account user attempts to access an encrypted resource?

  5. 5

    You are implementing cross-account encryption using AWS KMS. You have granted the external account's root user 'kms:Decrypt' in the Key Policy. Why might this still fail if the external account's IAM user tries to decrypt the data?