exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 495 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 495
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company wants to deny a specific federated user named Bob access to an Amazon S3 bucket named DOC-EXAMPLE-BUCKET. The company wants to meet this requirement by using a bucket policy. The company also needs to ensure that this bucket policy affects Bob's S3 permissions only. Any other permissions that Bob has must remain intact.

Which policy should the company use to meet these requirements?

  • A.
  • B.
  • C.
  • D.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
yorkicurke
1 year, 3 months ago
Selected Answer: B
Eliminating the rest; Option A: This policy allows all S3 actions for the federated user Bob on the DOC-EXAMPLE-BUCKET. Option C: The question specifies a federated user, not an IAM user. Therefore, this policy would not affect the intended user. Option D: Same as above, this option does not specify a federated user, it is asking for an assumed role. Therefore, this policy would not affect the intended user.
upvoted 1 times
...
danielklein09
1 year, 10 months ago
Selected Answer: B
Deny + federated user Bob
upvoted 3 times
...
Mark1000
1 year, 10 months ago
B Example bottom page: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_control-access_getfederationtoken.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago