SCS-C02 exam dumps

SCS-C02 practice question 281 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 281

Select 2

Your company has implemented a multi-account strategy in AWS and uses AWS Organizations to manage all accounts. You need to design an authentication mechanism to allow developers in the 'Dev' account to securely access resources in the 'Prod' account. The solution must follow AWS best practices, ensure least privilege, and minimize operational overhead. What steps should you take?

  1. A

    Enable AWS SSO in the management account and configure permission sets for developers to access resources in the 'Prod' account.

  2. B

    Create an IAM role in the 'Prod' account with necessary permissions and allow the 'Dev' account to assume this role.

  3. C

    Use cross-account IAM users in the 'Prod' account to grant developers in the 'Dev' account access to the required resources.

  4. D

    Set up a resource-based policy on the resources in the 'Prod' account to allow access from the developers' IAM roles in the 'Dev' account.

  5. E

    Configure an Amazon Cognito identity pool to authenticate developers and grant access to resources in the 'Prod' account.

Show answer and explanation

Correct answers: B, D

Explanation

The best solution for cross-account access between AWS accounts is to use IAM roles in conjunction with resource-based policies. By creating an IAM role in the 'Prod' account and allowing the 'Dev' account to assume it, you ensure secure, scalable, and least-privilege access. Optionally, resource-based policies can be configured directly on resources to allow access from specific accounts or roles. Both methods align with AWS's recommended practices for cross-account authentication and access control.

  • A. Incorrect.

    While AWS SSO can simplify access management across accounts, the question specifically asks for a solution that minimizes operational overhead and follows least privilege. AWS SSO is a valid solution but not the best fit for this scenario.

  • B. Correct.

    Creating an IAM role in the 'Prod' account and allowing the 'Dev' account to assume that role is a recommended cross-account access strategy. It follows the principle of least privilege and ensures secure authentication.

  • C. Incorrect.

    Using cross-account IAM users is not a recommended AWS best practice as it leads to higher operational overhead and does not scale well in a multi-account setup.

  • D. Correct.

    Configuring a resource-based policy is a valid method to allow cross-account access. It ensures the least privilege principle is followed and provides an alternative to role-based access control.

  • E. Incorrect.

    Amazon Cognito is used for authenticating end-users (such as application users) and managing identities, not for granting cross-account access to developers or AWS resources in this context.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam