AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A financial services company operates a critical application using a Multi-AZ Amazon RDS for PostgreSQL database in the us-east-1 Region. The database is encrypted at rest with a customer-managed AWS KMS key (CMK), also in us-east-1. The company has a disaster recovery plan with an RPO of 24 hours and an RTO of 4 hours, which requires the ability to restore the database in the us-west-2 Region. A solutions architect needs to design an automated and cost-effective solution to meet these requirements. Which approach should the architect choose?
Configure an automated process to create a daily manual snapshot of the RDS instance. Use the AWS CLI to copy the encrypted snapshot object directly to a versioned Amazon S3 bucket in us-west-2. In a disaster, restore the database from the S3 object.
Use AWS Backup to create daily cross-region copies of the RDS backups to a backup vault in us-west-2. In a disaster, restore the database from the copied backup in us-west-2, specifying the original KMS key from us-east-1 for decryption.
Automate a daily process to copy the latest RDS snapshot to the us-west-2 Region. During the copy operation, specify a CMK in us-west-2 to re-encrypt the snapshot. In a disaster, restore the database in us-west-2 from the copied snapshot.
Create a cross-region read replica of the RDS instance in us-west-2. In a disaster, promote the read replica to a standalone instance. Ensure the CMK from us-east-1 is configured as a multi-region key and replicated to us-west-2 to handle decryption.
The correct approach involves automating the copy of an RDS snapshot to the disaster recovery (DR) region and re-encrypting it with a KMS key local to that region. AWS KMS keys are regional resources, so a key from us-east-1 cannot be used to encrypt or decrypt resources in us-west-2. When copying an encrypted snapshot across regions, you must specify a KMS key in the destination region to encrypt the new snapshot copy. This method aligns with the backup and restore DR strategy, which is the most cost-effective solution for the given RPO of 24 hours and RTO of 4 hours.
The option to use a cross-region read replica describes a warm standby or pilot light approach. This is more expensive than necessary for the specified RPO and RTO. Furthermore, standard KMS keys cannot be replicated; you would need to create a multi-region key, which is a different and more complex setup.
The option suggesting the use of the original KMS key from us-east-1 in the us-west-2 region is incorrect because KMS keys are region-specific.
The option to copy the snapshot object directly to an S3 bucket is incorrect. The proper method is to use the CopyDBSnapshot API action (or the equivalent console/AWS Backup function), which handles the transfer and re-encryption. You do not manually copy the underlying snapshot files to S3 for this purpose.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why do KMS keys need to be region-specific for cross-region operations?
Open an interactive chat with Bash
What makes the snapshot copy approach the most cost-effective for this scenario?
Open an interactive chat with Bash
How does the CopyDBSnapshot API handle snapshot transfer and encryption?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .