AWS Certified Big Data - Specialty (#83)

An Amazon Redshift Database is encrypted using KMS. A data engineer needs to use the AWS CLI to create a KMS encrypted snapshot of the database in another AWS region. Which three steps should the data engineer take to accomplish this task? (Choose three.)

Create a new KMS key in the destination region.
Copy the existing KMS key to the destination region.
Use CreateSnapshotCopyGrant to allow Amazon Redshift to use the KMS key from the source region.
In the source region, enable cross-region replication and specify the name of the copy grant created.
In the destination region, enable cross-region replication and specify the name of the copy grant created.
Use CreateSnapshotCopyGrant to allow Amazon Redshift to use the KMS key created in the destination region.

Need help?