ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 441 - DOP-C01 discussion

Report
Export

A company has multiple child accounts that are part of an organization in AWS Organizations. The security team needs to review every Amazon EC2 security group and their inbound and outbound rules. The security team wants to programmatically retrieve this information from the child accounts using an AWS Lambda function in the management account of the organization. Which combination of access changes will meet these requirements? (Choose three.)

A.
Create a trust relationship that allows users in the child accounts to assume the management account IAM role.
Answers
A.
Create a trust relationship that allows users in the child accounts to assume the management account IAM role.
B.
Create a trust relationship that allows users in the management account to assume the IAM roles of the child accounts.
Answers
B.
Create a trust relationship that allows users in the management account to assume the IAM roles of the child accounts.
C.
Create an IAM role in each child account that has access to the AmazonEC2ReadOnlyAccess managed policy.
Answers
C.
Create an IAM role in each child account that has access to the AmazonEC2ReadOnlyAccess managed policy.
D.
Create an IAM role in each child account to allow the sts:AssumeRole action against the management account IAM role’s ARN.
Answers
D.
Create an IAM role in each child account to allow the sts:AssumeRole action against the management account IAM role’s ARN.
E.
Create an IAM role in the management account that allows the sts:AssumeRole action against the child account IAM role’s ARN.
Answers
E.
Create an IAM role in the management account that allows the sts:AssumeRole action against the child account IAM role’s ARN.
F.
Create an IAM role in the management account that has access to the AmazonEC2ReadOnlyAccess managed policy.
Answers
F.
Create an IAM role in the management account that has access to the AmazonEC2ReadOnlyAccess managed policy.
Suggested answer: B, C, E

Explanation:

Reference: https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_cross-account-with-roles.html

https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_accounts_access.html

asked 16/09/2024
Marcin Piotrowski
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first