DVA-C02 exam dumps

DVA-C02 practice question 145 of 399

AWS Certified Developer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DVA-C02 Question 145

Single answer

You are developing an application that stores its data in an Amazon S3 bucket. The application needs to grant read-only access to specific users while ensuring others cannot access the data. You decide to use ACLs (Access Control Lists) to control access. Which of the following statements is correct when using ACLs for this purpose?

  1. A

    ACLs can be used to grant permissions to individual AWS accounts or predefined groups, like 'AllUsers' or 'AuthenticatedUsers'.

  2. B

    ACLs can be applied at the bucket level only, not at the object level.

  3. C

    ACLs are a suitable mechanism to enforce fine-grained permissions for IAM users.

  4. D

    ACLs can be used to define cross-account access without requiring additional policies.

Show answer and explanation

Correct answer: A

Explanation

ACLs in Amazon S3 are a low-level access control mechanism that can grant permissions to individual AWS accounts or predefined groups. They are ideal for simple access control needs, but they lack the flexibility and granularity of IAM policies or bucket policies. In this question, the correct answer highlights the ability of ACLs to grant permissions to specific AWS accounts or groups.

  • A. Correct.

    This is correct. ACLs in Amazon S3 allow granting permissions to specific AWS accounts or predefined groups such as 'AllUsers' or 'AuthenticatedUsers'. This makes them suitable for use cases requiring simple access control mechanisms.

  • B. Incorrect.

    This is incorrect. S3 ACLs can be applied to both buckets and objects, allowing control over access at both levels.

  • C. Incorrect.

    This is incorrect. ACLs are not the best mechanism to enforce fine-grained permissions for IAM users. IAM policies are better suited for this purpose.

  • D. Incorrect.

    This is partially correct, but misleading. While ACLs can define cross-account access, they often lack the flexibility and scalability required for complex access control scenarios. IAM policies are preferred for managing such access.

Timed practice exam

Take a DVA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam