SCS-C02 exam dumps

SCS-C02 practice question 308 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 308

Select 2

Your company has recently implemented an S3 bucket to store financial reports. These reports must only be accessible to users in the 'Finance' IAM group, and the bucket should not allow access from any other users, including the root account. Which of the following IAM policy configurations should you implement to meet these requirements?

  1. A

    Attach an identity-based policy to the 'Finance' IAM group that grants 's3:GetObject' and 's3:PutObject' permissions for the bucket.

  2. B

    Attach a resource-based bucket policy to the S3 bucket that explicitly denies access to all users except those in the 'Finance' IAM group.

  3. C

    Attach an inline policy to the 'Finance' IAM group that grants full access to the S3 bucket.

  4. D

    Attach a managed policy to the 'Finance' IAM group and configure the bucket ACL to allow access only to the group.

  5. E

    Use a bucket policy to deny all actions for the root account while granting the 'Finance' IAM group access to the S3 bucket.

Show answer and explanation

Correct answers: B, E

Explanation

To meet the requirements, you need to ensure that only the 'Finance' IAM group can access the S3 bucket and that no other users, including the root account, have access. A combination of a resource-based bucket policy (Option 2) and a bucket policy to explicitly deny root account access (Option 5) ensures the access restrictions are properly enforced. Identity-based or inline policies alone are insufficient since they cannot restrict access for the root account or other users outside the group.

  • A. Incorrect.

    This option allows the 'Finance' IAM group access to the S3 bucket, but it does not prevent others, including the root account, from accessing the bucket, which violates the requirements.

  • B. Correct.

    A resource-based bucket policy can explicitly deny access to all users except those in the 'Finance' IAM group. This method ensures access is restricted as required.

  • C. Incorrect.

    An inline policy for the 'Finance' IAM group can provide access, but it won’t prevent other users, including the root account, from accessing the bucket.

  • D. Incorrect.

    A managed policy can grant access to the 'Finance' IAM group, but using an ACL to restrict access is not suitable for fine-grained permissions like explicitly denying access to the root account.

  • E. Correct.

    A bucket policy can be used to explicitly deny all actions for the root account while granting access to the 'Finance' IAM group. This meets the security requirement of denying root account access.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam