Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 429 discussion

The following IAM policy is attached to an IAM group. This is the only policy applied to the group.



What are the effective IAM permissions of this policy for group members?

  • A. Group members are permitted any Amazon EC2 action within the us-east-1 Region. Statements after the Allow permission are not applied.
  • B. Group members are denied any Amazon EC2 permissions in the us-east-1 Region unless they are logged in with multi-factor authentication (MFA).
  • C. Group members are allowed the ec2:StopInstances and ec2:TerminateInstances permissions for all Regions when logged in with multi-factor authentication (MFA). Group members are permitted any other Amazon EC2 action.
  • D. Group members are allowed the ec2:StopInstances and ec2:TerminateInstances permissions for the us-east-1 Region only when logged in with multi-factor authentication (MFA). Group members are permitted any other Amazon EC2 action within the us-east-1 Region.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
jack79
Highly Voted 1 year, 5 months ago
came in exam today
upvoted 12 times
...
KennethNg923
Most Recent 5 months, 1 week ago
Selected Answer: D
for the us-east-1 Region only, not for all region
upvoted 1 times
...
wizcloudifa
7 months, 1 week ago
Selected Answer: D
One of the few situations when actual answer is same as the most voted answer lol
upvoted 1 times
...
pdragon1981
10 months, 4 weeks ago
Selected Answer: C
Not sure why everyone vote D, I think that the valid option as to be C as the second condition regarding MFA there is point that only refer to a specific region, so basically this means that is for all the regions
upvoted 2 times
pdragon1981
10 months, 4 weeks ago
Ok ignore D is right as the first condition is what gives permission to make anything for EC2 but is restricted to us-east-1 region
upvoted 5 times
...
...
youdelin
1 year, 1 month ago
the json is describing a lot of things apparently, so I go with the longest answer lol
upvoted 1 times
...
Guru4Cloud
1 year, 2 months ago
Selected Answer: D
D. Group members are allowed the ec2:StopInstances and ec2:TerminateInstances permissions for the us-east-1 Region only when logged in with multi-factor authentication (MFA). Group members are permitted any other Amazon EC2 action within the us-east-1 Region
upvoted 2 times
...
james2033
1 year, 4 months ago
Selected Answer: D
A. "Statements after the Allow permission are not applied." --> Wrong. B. "denied any Amazon EC2 permissions in the us-east-1 Region" --> Wrong. Just deny 2 items. C. "allowed the ec2:StopInstances and ec2:TerminateInstances permissions for all Regions" --> Wrong. Just region us-east-1. D. ok.
upvoted 1 times
...
TariqKipkemei
1 year, 5 months ago
Selected Answer: D
Only D makes sense
upvoted 1 times
...
antropaws
1 year, 5 months ago
Selected Answer: D
D sounds about right.
upvoted 1 times
...
alvinnguyennexcel
1 year, 6 months ago
Selected Answer: D
D is correct
upvoted 2 times
...
omoakin
1 year, 6 months ago
D is correct
upvoted 1 times
...
nosense
1 year, 6 months ago
Selected Answer: D
D is right
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...