ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 222 - DOP-C01 discussion

Report
Export

A government agency is storing highly confidential files in an encrypted Amazon S3 bucket. The agency has configured federated access and has allowed only a particular on-premises Active Directory user group to access this bucket. The agency wants to maintain audit records and automatically detect and revert any accidental changes administrators make to the IAM policies used for providing this restricted federated access. Which of the following options provide the FASTEST way to meet these requirements?

A.
Configure an Amazon CloudWatch Events Event Bus on an AWS CloudTrail API for triggering the AWS Lambda function that detects and reverts the change.
Answers
A.
Configure an Amazon CloudWatch Events Event Bus on an AWS CloudTrail API for triggering the AWS Lambda function that detects and reverts the change.
B.
Configure an AWS Config rule to detect the configuration change and execute an AWS Lambda function to revert the change.
Answers
B.
Configure an AWS Config rule to detect the configuration change and execute an AWS Lambda function to revert the change.
C.
Schedule an AWS Lambda function that will scan the IAM policy attached to the federated access role for detecting and reverting any changes.
Answers
C.
Schedule an AWS Lambda function that will scan the IAM policy attached to the federated access role for detecting and reverting any changes.
D.
Restrict administrators in the on-premises Active Directory from changing the IAM policies.
Answers
D.
Restrict administrators in the on-premises Active Directory from changing the IAM policies.
Suggested answer: B
asked 16/09/2024
Abheesh Vijayan
24 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first