An AWS account owner has setup multiple IAM users. One IAM user only has CloudWatch access. He has setup the alarm action which stops the EC2 instances when the CPU utilization is below the threshold limit. What will happen in this case?
A.
It is not possible to stop the instance using the CloudWatch alarm
B.
CloudWatch will stop the instance when the action is executed
C.
The user cannot set an alarm on EC2 since he does not have the permission
D.
The user can setup the action but it will not be executed if the user does not have EC2 rights
Suggested Answer:D🗳️
Amazon CloudWatch alarms watch a single metric over a time period that the user specifies and performs one or more actions based on the value of the metric relative to a given threshold over a number of time periods. The user can setup an action which stops the instances when their CPU utilization is below a certain threshold for a certain period of time. The EC2 action can either terminate or stop the instance as part of the EC2 action. If the IAM user has read/write permissions for Amazon CloudWatch but not for Amazon EC2, he can still create an alarm. However, the stop or terminate actions will not be performed on the Amazon EC2 instance.
In this scenario, the IAM user with CloudWatch access can set up the alarm action to stop EC2 instances when the CPU utilization is below the threshold limit. However, the action will not be executed if the user does not have the necessary EC2 rights. The user must have the appropriate permissions to interact with EC2 instances in order for the action to be executed successfully.
Really odd question, as we dont know what permissions have been granted. Assumption is none, so the answer is correct.
https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/UsingAlarmActions.html
Via Cloudwatch - a service linked role "AWSServiceRoleForCloudWatchEvents" is needed. If done via an IAM account, you need "iam:CreateServiceLinkedRole permission".
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
albert_kuo
4 months, 3 weeks agoFinger41
1 year, 4 months ago