SCS-C02 exam dumps

SCS-C02 practice question 278 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 278

Single answer

An organization needs to grant developers temporary access to an Amazon S3 bucket for testing purposes. The developers should only be able to access the bucket during a specific time window and must have the least privilege required to perform their work. How can the organization achieve this using AWS Identity and Access Management (IAM)?

  1. A

    Use an IAM role with a trust policy and configure the developers to assume the role with a time-limited session.

  2. B

    Create an IAM user for each developer with time-restricted access keys and attach an S3 access policy.

  3. C

    Attach an S3 bucket policy with specific time conditions granting access to the developers’ IAM users.

  4. D

    Configure a service control policy (SCP) in AWS Organizations to restrict access by time for the developers.

Show answer and explanation

Correct answer: A

Explanation

Using IAM roles with a trust policy allows developers to assume the role and gain temporary credentials for accessing the S3 bucket within a defined session duration. This approach avoids the need for long-lived credentials and aligns with AWS security best practices for granting least privilege and temporary access.

  • A. Correct.

    This is the correct answer. By using an IAM role with a trust policy, developers can assume the role with temporary credentials that are valid for a specific time period. This approach adheres to the principle of least privilege and does not require creating long-lived credentials.

  • B. Incorrect.

    This is incorrect. While IAM users could be configured with access keys, these are long-lived credentials and do not enforce a specific time limit. This approach does not align with best practices for temporary access.

  • C. Incorrect.

    This is incorrect. S3 bucket policies can restrict access based on conditions, but there is no built-in mechanism to enforce temporary access for a specific time window in this scenario.

  • D. Incorrect.

    This is incorrect. SCPs are used to manage permissions across accounts in an organization, not for granting temporary access to resources like an S3 bucket.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam