Courseiva

DEA-C01 Data Security and Governance Practice Question

A company uses Amazon RDS for PostgreSQL with encryption at rest using AWS KMS. The company needs to share a database snapshot with a different AWS account. What must be done to allow the target account to restore the snapshot?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Share the snapshot and update the KMS key policy to allow the target account to use the key

Cross-account snapshot sharing of an encrypted snapshot requires both sharing the snapshot and granting the target account permission to use the KMS key via the key policy. Option A is incorrect because copying does not grant the necessary key access. Option B is incorrect because IAM roles are not used for this purpose; KMS key policies are the mechanism for cross-account access. Option D is incorrect because encryption cannot be disabled on an existing encrypted snapshot.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Copy the snapshot to the target account's region and share it

    Why it's wrong here

    Copying to the target account's region creates a separate snapshot owned by the source account, so the target still cannot restore it unless that copy is shared. For an encrypted snapshot, the source must share it directly and grant the target's KMS key access. Cross-region copying suits disaster recovery, not cross-account sharing.

  • ✗

    Create an IAM role in the source account that allows cross-account snapshot access

    Why it's wrong here

    An IAM role cannot grant cross-account access to an encrypted RDS snapshot; sharing encrypted snapshots requires a KMS key policy granting the target account decrypt and grant permissions, plus snapshot sharing itself. IAM roles suit cross-account API access, such as assuming a role to call RDS, not KMS key authorisation for snapshot restoration.

  • ✓

    Share the snapshot and update the KMS key policy to allow the target account to use the key

    Why this is correct

    Sharing an encrypted RDS snapshot requires the target account to decrypt it, so the KMS key policy must grant that account kms:Decrypt and kms:CreateGrant. Without this key-policy change, the shared snapshot cannot be restored, because the target account lacks permission to use the customer-managed key.

  • ✗

    Disable encryption on the snapshot before sharing

    Why it's wrong here

    Disabling encryption on an RDS snapshot is impossible; KMS-encrypted snapshots stay encrypted, and only the key policy governs cross-account access. It tempts because unencrypted snapshots can be shared freely, so removing encryption would sidestep key permissions — but the actual requirement is granting the target account kms:DescribeKey and kms:CreateGrant, then sharing the snapshot.

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.