CLF-C02 exam dumps

CLF-C02 practice question 99 of 342

AWS Certified Cloud Practitioner. Free level, Amazon Web Services. Free question with the correct answer and a full explanation.

CLF-C02 Question 99

Select 2

You are a cloud administrator setting up access controls for a development team in your organization. The team needs full access to manage Amazon S3 buckets but should not be able to make any changes to IAM policies or view billing information. Which AWS access management capabilities should you use to achieve this?

  1. A

    Create an IAM policy granting full access to Amazon S3 and attach it to the development team’s IAM group.

  2. B

    Use Service Control Policies (SCPs) to restrict the team's access to IAM and billing services.

  3. C

    Enable AWS Organizations to centrally manage permissions for all users in the team.

  4. D

    Use IAM roles to give the team temporary permissions when accessing Amazon S3.

  5. E

    Use resource-based policies to control access to individual S3 buckets.

Show answer and explanation

Correct answers: A, B

Explanation

To achieve the goal of granting full access to Amazon S3 while restricting access to IAM and billing, you should use a combination of IAM policies to grant the required permissions and Service Control Policies (SCPs) to enforce restrictions. This ensures that the development team has the necessary access to perform their tasks without exceeding their scope of responsibility.

  • A. Correct.

    This is correct because IAM policies define fine-grained permissions and can be used to grant access to specific services like Amazon S3.

  • B. Correct.

    This is correct because SCPs can be used to enforce restrictions on access to IAM and billing services at the organizational level.

  • C. Incorrect.

    This is incorrect because AWS Organizations is a management tool for multiple AWS accounts, not a direct mechanism for granting or restricting permissions within an account.

  • D. Incorrect.

    This is incorrect because IAM roles are used for granting temporary access between entities but are not necessary in this scenario where long-term permissions are required.

  • E. Incorrect.

    This is incorrect because resource-based policies are used to grant access to specific resources, but they do not restrict access to broader services like IAM or billing.

Timed practice exam

Take a CLF-C02 practice test under exam conditions

65 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam