exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 733 discussion

Exam question from Amazon's AWS-SysOps
Question #: 733
Topic #: 1
[All AWS-SysOps Questions]

A SysOps Administrator implemented the following bucket policy to allow only the corporate IP address range of 54.240.143.0/24 to access objects in an Amazon
S3 bucket.

Some employees are reporting that they are able to access the S3 bucket from IP addresses outside the corporate IP address range.
How can the Administrator address this issue?

  • A. Modify the Condition operator to include both NotIpAddress and IpAddress to prevent unauthorized access to the S3 bucket.
  • B. Modify the Condition element from the IAM policy to aws:StringEquals instead of aws:SourceIp.
  • C. Modify the IAM policy instead of the bucket policy to restrict users from accessing the bucket based on their source IP addresses.
  • D. Change Effect from Allow to Deny in the second statement of the policy to deny requests not from the source IP range.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Reference:
https://aws.amazon.com/premiumsupport/knowledge-center/block-s3-traffic-vpc-ip/

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TroyMcLure
5 months, 4 weeks ago
Correct Answer: D Another approach could be used by changing the "NotIpAddress" by "IpAddress", keeping the Effect: Allow.
upvoted 1 times
...
RicardoD
6 months ago
D is the answer The way the original policy is, it is denying the IP it should allow
upvoted 1 times
...
Azaad78
6 months, 1 week ago
D - is ok
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago