SAP-C02 exam dumps

SAP-C02 practice question 225 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 225

Select 2

Your organization uses AWS Organizations to manage multiple accounts. You need to allow a group of developers in one account to access an S3 bucket in another account within the same organization. The access must be limited to specific actions (GET and PUT) on the bucket and should not require the use of long-term credentials. How can you achieve this?

  1. A

    Create a resource-based policy on the S3 bucket granting access to the developers' IAM roles and specify the required actions.

  2. B

    Use AWS Single Sign-On (SSO) to allow developers to access the bucket by logging into the AWS Management Console.

  3. C

    Create an IAM policy in the developers' account and attach it to their IAM roles, specifying permissions to access the S3 bucket.

  4. D

    Enable cross-account access by creating a trust relationship in the bucket owner's account and use IAM roles to grant temporary access.

  5. E

    Use an SCP (Service Control Policy) in AWS Organizations to grant the necessary permissions for the developers to access the S3 bucket.

Show answer and explanation

Correct answers: A, D

Explanation

To enable cross-account access to an S3 bucket, you can use a combination of resource-based policies and IAM roles. Resource-based policies on the bucket grant access to specific IAM entities in another account, while IAM roles with a trust relationship allow developers to assume the role and gain temporary permissions. This approach avoids the need for long-term credentials and ensures fine-grained access control.

  • A. Correct.

    Correct: A resource-based policy on the S3 bucket can directly grant cross-account access to the developers' IAM roles and limit access to the required actions.

  • B. Incorrect.

    Incorrect: AWS Single Sign-On (SSO) is primarily used for user login and session management across accounts. It does not directly control or grant access to AWS resources like S3 buckets.

  • C. Incorrect.

    Incorrect: IAM policies in the developers' account cannot directly grant access to resources in another account. Cross-account access requires additional configuration, such as resource-based policies or role assumption.

  • D. Correct.

    Correct: A trust relationship between accounts allows developers to assume an IAM role in the account owning the bucket, enabling temporary access with the required permissions.

  • E. Incorrect.

    Incorrect: SCPs are used to set permission boundaries at the organizational level and cannot be used to directly grant access to specific resources like S3 buckets.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam