SCS-C02 exam dumps

SCS-C02 practice question 371 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 371

Single answer

An organization uses an Amazon S3 bucket to store sensitive financial reports. The bucket must allow access only to users from the organization's AWS account, and access must be denied to requests originating from other accounts, even if those requests include valid temporary credentials. Which resource policy configuration will satisfy this requirement?

  1. A

    A policy that explicitly denies access to all principals except those in the organization's account ID.

  2. B

    A policy that explicitly allows access to the bucket for principals in the organization's account ID and omits a Deny statement.

  3. C

    A policy that includes an explicit Deny statement for all principals not in the organization's account ID, and an explicit Allow statement for the organization's account ID.

  4. D

    A policy that includes only an explicit Allow statement for the organization's account ID.

Show answer and explanation

Correct answer: C

Explanation

Resource policies need to explicitly define both Allow and Deny statements to precisely control access. In this case, the organization must deny access to all principals outside its account while allowing access for its own account. The correct answer ensures that no unintended access is granted, even if valid temporary credentials are used by other accounts.

  • A. Incorrect.

    This option is incorrect because while it denies access, it does not include the required Allow statement for users from the organization's account. Both Allow and Deny statements are needed to explicitly define permissions.

  • B. Incorrect.

    This option is incorrect because omitting a Deny statement could allow unintended access through other methods, such as cross-account roles or policies with higher precedence.

  • C. Correct.

    This is the correct answer because it explicitly denies access to all principals not in the organization's account ID and explicitly allows access for the organization's account ID. This ensures that only users from the organization's account can access the S3 bucket, even if valid temporary credentials are provided by another account.

  • D. Incorrect.

    This option is incorrect because an Allow statement alone is insufficient. Without an explicit Deny for other principals, requests from other accounts could still gain access under certain conditions.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam