Ultimate access to all questions.
In a multi-account AWS environment, the sales team stores large amounts of data in an encrypted Amazon S3 bucket, while the marketing team utilizes Amazon QuickSight for data visualization. The marketing team requires access to the sales team's S3 data, which is encrypted with an AWS KMS key. The marketing team has already established an IAM service role for QuickSight in their account. What is the most efficient and secure method to grant the marketing team access to the sales team's S3 data without excessive operational overhead?