exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 351 discussion

A company is managing multiple AWS accounts in AWS Organizations. The company is reviewing internal security of its AWS environment. The company’s security administrator has their own AWS account and wants to review the VPC configuration of developer AWS accounts.

Which solution will meet these requirements in the MOST secure manner?

  • A. Create an IAM policy in each developer account that has read-only access related to VPC resources. Assign the policy to an IAM user. Share the user credentials with the security administrator.
  • B. Create an IAM policy in each developer account that has administrator access to all Amazon EC2 actions, including VPC actions. Assign the policy to an IAM user. Share the user credentials with the security administrator.
  • C. Create an IAM policy in each developer account that has administrator access related to VPC resources. Assign the policy to a cross-account IAM role. Ask the security administrator to assume the role from their account.
  • D. Create an IAM policy in each developer account that has read-only access related to VPC resources. Assign the policy to a cross-account IAM role. Ask the security administrator to assume the role from their account.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
james2033
9 months, 3 weeks ago
Selected Answer: D
read-only --> A, D. Assign policy to an IAM user --> remove A. Choose D.
upvoted 1 times
...
james2033
9 months, 3 weeks ago
Selected Answer: D
A, D --> read-only access. D: cross-account IAM role --> Choose D.
upvoted 1 times
...
LudiVoss
1 year, 3 months ago
Selected Answer: D
D because I am D best admin in the world right now.
upvoted 3 times
...
seifskl
1 year, 7 months ago
Selected Answer: D
The most secure way to provide access between AWS accounts is by using IAM roles with cross-account access. And also, the security administrator only needs read-only access to review the VPC configuration.
upvoted 3 times
...
[Removed]
1 year, 8 months ago
Selected Answer: D
When you set permissions with IAM policies, grant only the permissions required to perform a task. You do this by defining the actions that can be taken on specific resources under specific conditions, also known as least-privilege permissions. https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html
upvoted 2 times
...
Christina666
1 year, 9 months ago
Selected Answer: D
d..........
upvoted 2 times
...
[Removed]
1 year, 9 months ago
The most secure way for the security administrator to review the VPC configuration of developer AWS accounts would be to create an IAM policy in each developer account that has read-only access related to VPC resources and assign the policy to a cross-account IAM role. The security administrator can then assume the role from their own account to review the VPC configuration. This approach avoids sharing user credentials and provides the security administrator with the necessary permissions to review the VPC configuration without granting unnecessary access. So, the correct answer would be D. Create an IAM policy in each developer account that has read-only access related to VPC resources. Assign the policy to a cross-account IAM role. Ask the security administrator to assume the role from their account.
upvoted 4 times
...
tex23
1 year, 9 months ago
Selected Answer: C
Answer C; a dev account with read-only access to VPC is ok whereas a dev account with admin access to VPC requires review.
upvoted 1 times
...
tex23
1 year, 9 months ago
Answer C; a dev account with read-only access to VPC is ok whereas a dev account with admin access to VPC requires review.
upvoted 1 times
...
guau
1 year, 9 months ago
D , AWS = AlWays aSume the role
upvoted 1 times
...
Pete987
1 year, 10 months ago
Selected Answer: D
D is the answer
upvoted 1 times
...
kevino81
1 year, 10 months ago
Selected Answer: D
security administrator has their own AWS account so you should use cross-account and read only to follow least privilege principle
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago