[Infrastructure Security]A company has a batch-processing system that uses Amazon S3, Amazon EC2, and AWS Key Management Service (AWS KMS). The system uses two AWS accounts: Account A and Account B.Account A hosts an S3 bucket that stores the objects that will be processed. The S3 bucket also stores the results of the processing. All the S3 bucket objects are encrypted by a KMS key that is managed inAccount A.Account B hosts a VPC that has a fleet of EC2 instances that access the S3 buck-et in Account A by using statements in the bucket policy. The VPC was created with DNS hostnames enabled and DNS resolution enabled.A security engineer needs to update the design of the system without changing any of the system's code. No AWS API calls from the batch-processing EC2 in-stances can travel over the internet.Which combination of steps will meet these requirements? (Select TWO.)
A. In the Account B VPC, create a gateway VPC endpoint for Amazon S3
B. In the Account B VPC, create an interface VPC endpoint for Amazon S3
C. In the Account B VPC, create an interface VPC endpoint for AWS KMS
D. In the Account B VPC, create an interface VPC endpoint for AWS KMS
E. In the Account B VPC, verify that the S3 bucket policy allows the s3:PutObjectAcl action for cross-account use