AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An operations team uses an EC2 Image Builder pipeline to produce an Amazon Linux 2 AMI each month. The image must be encrypted with a customer managed KMS key, scanned for vulnerabilities, versioned, and shared with two other AWS accounts in us-east-1 and eu-west-1. The first build succeeds, but the AMI is not visible to the peer accounts. Which additional configuration will let the encrypted AMI be distributed?

  • Turn off encryption because encrypted AMIs cannot be shared across AWS accounts through Image Builder.

  • Create a separate Image Builder pipeline in each target account; encrypted images cannot be distributed cross-account from a single pipeline.

  • Add the target account IDs to the pipeline's distribution settings and select "Share encrypted AMI"; Image Builder will automatically handle key permissions.

  • Encrypt the image with a customer managed KMS key that includes grants for the target accounts, then list those accounts in the distribution settings.

AWS Certified CloudOps Engineer Associate SOA-C03
Deployment, Provisioning, and Automation
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot