DEA-C01 exam dumps

DEA-C01 practice question 458 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 458

Select 3

An organization uses Amazon S3 to store sensitive financial data. They want to enforce access control by ensuring that only specific IAM roles and users with certain attributes or tags can access these S3 buckets. How can they achieve this using AWS features?

  1. A

    Use IAM policies to define role-based access control for specific IAM roles.

  2. B

    Use S3 bucket policies to implement tag-based access control for resources and users.

  3. C

    Use S3 Access Points to enforce attribute-based access control for different user groups.

  4. D

    Use AWS Organizations Service Control Policies (SCPs) to define tag-based access control for S3 buckets.

  5. E

    Use IAM identity-based policies with Conditions that filter access based on resource tags and user attributes.

Show answer and explanation

Correct answers: A, B, E

Explanation

To enforce access control for S3 buckets based on roles, tags, or user attributes, you can use a combination of IAM policies, S3 bucket policies, and Conditions in IAM identity-based policies. Role-based access control can be achieved with IAM policies, while tag-based and attribute-based access controls can be enforced using S3 bucket policies or Conditions in IAM identity-based policies.

  • A. Correct.

    Correct: IAM policies can be used to define role-based access control, limiting access to specific IAM roles based on permissions.

  • B. Correct.

    Correct: S3 bucket policies support tag-based access control, allowing you to write conditions based on resource or user tags.

  • C. Incorrect.

    Incorrect: S3 Access Points are used to manage access to S3 buckets for large-scale data access patterns, but they do not directly enforce attribute-based access control.

  • D. Incorrect.

    Incorrect: SCPs are used to manage permissions at the account level in AWS Organizations, but they cannot directly enforce tag-based access control for S3 buckets.

  • E. Correct.

    Correct: IAM identity-based policies can use Conditions to filter access based on resource tags and user attributes, enabling fine-grained access controls.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam