DEA-C01 exam dumps

DEA-C01 practice question 457 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 457

Select 2

A company is using Amazon S3 to store sensitive financial data. They want to enforce strict access controls by allowing only certain IAM roles to perform specific actions on S3 buckets, while also ensuring that access can be dynamically managed based on tags applied to the resources. Which combination of authorization methods should they use to meet this requirement?

  1. A

    Role-based access control (RBAC) using IAM roles

  2. B

    Policy-based access control using IAM policies

  3. C

    Tag-based access control using resource tags and IAM policies

  4. D

    Attribute-based access control using custom attributes in AWS Cognito

  5. E

    Bucket policies to enforce access permissions at the bucket level

Show answer and explanation

Correct answers: B, C

Explanation

The combination of policy-based access control and tag-based access control is the best fit for the scenario. IAM policies allow for fine-grained control over permissions, and when paired with tag-based access control, they enable dynamic management of permissions based on resource tags. Role-based access control and bucket policies alone do not satisfy the requirement for dynamic tag-based management, and attribute-based access control is not applicable to this use case.

  • A. Incorrect.

    Role-based access control (RBAC) is useful for assigning permissions to specific IAM roles, but it does not provide dynamic management based on resource tags, which is a requirement in this scenario.

  • B. Correct.

    Policy-based access control using IAM policies is a core method for defining and enforcing permissions at a granular level, and it can work in conjunction with tag-based access control.

  • C. Correct.

    Tag-based access control allows permissions to be dynamically managed based on tags applied to AWS resources, making it a suitable choice for this use case.

  • D. Incorrect.

    Attribute-based access control using custom attributes in AWS Cognito is designed for application user permissions in Cognito, not for managing access to AWS resources like S3.

  • E. Incorrect.

    Bucket policies are an alternative way to enforce access at the bucket level, but they are not dynamic and do not utilize tags or IAM roles as specified in the requirements.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam