ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 896 - SAP-C01 discussion

Report
Export

A company is using multiple AWS accounts. The company has a shared services account and several other accounts (or different projects. A team has a VPC in a project account. The team wants to connect this VPC to a corporate network through an AWS Direct Connect gateway that exists in the shared services account. The team wants to automatically perform a virtual private gateway association with the Direct Connect gateway by using an already-tested AWS Lambda function while deploying its VPC networking stack. The Lambda function code can assume a role by using AWS Security Token Service (AWS STS). The team is using AWS Cloud Formation to deploy its infrastructure.

Which combination of steps will meet these requirements? (Select THREE.)

A.
Deploy the Lambda function to the project account. Update the Lambda function's 1AM role with the directconnect:* permission
Answers
A.
Deploy the Lambda function to the project account. Update the Lambda function's 1AM role with the directconnect:* permission
B.
Create a cross-account 1AM role in the shared services account that grants the Lambda function the directconnect:" permission. Add the sts:AssumeRo!e permission to the 1AM role that is associated with the Lambda function in the shared services account.
Answers
B.
Create a cross-account 1AM role in the shared services account that grants the Lambda function the directconnect:" permission. Add the sts:AssumeRo!e permission to the 1AM role that is associated with the Lambda function in the shared services account.
C.
Add a custom resource to the Cloud Formation networking stack that references the Lambda function in the project account.
Answers
C.
Add a custom resource to the Cloud Formation networking stack that references the Lambda function in the project account.
D.
Deploy the Lambda function that is performing the association to the shared services account.Update the Lambda function's 1AM role with the directconnect:' permission.
Answers
D.
Deploy the Lambda function that is performing the association to the shared services account.Update the Lambda function's 1AM role with the directconnect:' permission.
E.
Create a cross-account 1AM role in the shared services account that grants the sts: Assume Role permission to the Lambda function with the directconnect:" permission acting as a resource. Add the sts AssumeRole permission with this cross-account 1AM role as a resource to the 1AM role that belongs to the Lambda function in the project account.
Answers
E.
Create a cross-account 1AM role in the shared services account that grants the sts: Assume Role permission to the Lambda function with the directconnect:" permission acting as a resource. Add the sts AssumeRole permission with this cross-account 1AM role as a resource to the 1AM role that belongs to the Lambda function in the project account.
F.
Add a custom resource to the Cloud Formation networking stack that references the Lambda function in the shared services account.
Answers
F.
Add a custom resource to the Cloud Formation networking stack that references the Lambda function in the shared services account.
Suggested answer: B, C, E
asked 16/09/2024
Instel SL
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first