SAP-C02 exam dumps

SAP-C02 practice question 421 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 421

Select 3

A company is building a multi-tier web application on AWS and wants to ensure that it follows the principle of least privilege access. The application consists of an Amazon EC2 instance running a web server, an Amazon RDS database for storing user data, and an Amazon S3 bucket for user-uploaded files. You are tasked with designing the IAM policies to ensure the principle of least privilege is followed. Which of the following actions should you take to meet this requirement?

  1. A

    Attach an IAM role to the EC2 instance that allows only access to the specific S3 bucket and RDS instance needed by the application.

  2. B

    Create an IAM policy that grants full administrative privileges to the EC2 instance for future flexibility.

  3. C

    Use resource-level permissions in the IAM policies to grant access to specific S3 bucket objects and RDS databases.

  4. D

    Attach an IAM policy to the S3 bucket to allow public read and write access for user uploads for easier management.

  5. E

    Periodically review and refine IAM policies to ensure they only grant the necessary permissions.

Show answer and explanation

Correct answers: A, C, E

Explanation

The principle of least privilege access requires that entities (users, roles, applications, etc.) are granted only the permissions necessary to perform their tasks and no more. Options 1, 3, and 5 follow this principle by limiting permissions to specific resources, using resource-level permissions, and continuously reviewing policies. Options 2 and 4 violate the principle by granting excessive and unnecessary permissions.

  • A. Correct.

    This option aligns with the principle of least privilege by granting the EC2 instance only the necessary permissions to perform its tasks.

  • B. Incorrect.

    Granting full administrative privileges violates the principle of least privilege by providing unnecessary permissions.

  • C. Correct.

    Using resource-level permissions ensures that access is restricted to only the specific resources required, adhering to the principle of least privilege.

  • D. Incorrect.

    Allowing public read and write access to the S3 bucket violates security best practices and does not follow the principle of least privilege.

  • E. Correct.

    Regularly reviewing and refining IAM policies ensures permissions remain minimal and aligned with application needs, supporting the principle of least privilege.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam