AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An operations team uses an EC2 Image Builder pipeline to produce an Amazon Linux 2 AMI each month. The image must be encrypted with a customer managed KMS key, scanned for vulnerabilities, versioned, and shared with two other AWS accounts in us-east-1 and eu-west-1. The first build succeeds, but the AMI is not visible to the peer accounts. Which additional configuration will let the encrypted AMI be distributed?
Turn off encryption because encrypted AMIs cannot be shared across AWS accounts through Image Builder.
Create a separate Image Builder pipeline in each target account; encrypted images cannot be distributed cross-account from a single pipeline.
Add the target account IDs to the pipeline's distribution settings and select "Share encrypted AMI"; Image Builder will automatically handle key permissions.
Encrypt the image with a customer managed KMS key that includes grants for the target accounts, then list those accounts in the distribution settings.
Encrypted AMIs can be shared during the Image Builder distribution phase only if the AWS accounts that receive the image also have permission to use the KMS key that encrypts the underlying snapshots. Adding the account IDs to the distribution configuration is necessary, but it does not grant KMS access. Creating grants or key-policy statements on the customer managed key for the target accounts and then listing those accounts in the distribution settings satisfies both requirements. Disabling encryption or creating separate pipelines is unnecessary.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are KMS grants and how are they used in AMI sharing?
Open an interactive chat with Bash
Why is adding account IDs to distribution settings insufficient alone?
Open an interactive chat with Bash
How does Image Builder handle cross-account AMI distribution with encryption?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Deployment, Provisioning, and Automation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .