ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 290 - SAP-C02 discussion

Report
Export

A company manages hundreds of AWS accounts centrally in an organization in AWS Organizations.

The company recently started to allow product teams to create and manage their own S3 access points in their accounts. The S3 access points can be accessed only within VPCs not on the internet.

What is the MOST operationally efficient way to enforce this requirement?

A.
Set the S3 access point resource policy to deny the s3 CreateAccessPoint action unless the s3:AccessPointNetworkOngm condition key evaluates to VPC.
Answers
A.
Set the S3 access point resource policy to deny the s3 CreateAccessPoint action unless the s3:AccessPointNetworkOngm condition key evaluates to VPC.
B.
Create an SCP at the root level in the organization to deny the s3 CreateAccessPoint action unless the s3 AccessPomtNetworkOngin condition key evaluates to VPC.
Answers
B.
Create an SCP at the root level in the organization to deny the s3 CreateAccessPoint action unless the s3 AccessPomtNetworkOngin condition key evaluates to VPC.
C.
Use AWS CloudFormation StackSets to create a new 1AM policy in each AVVS account that allows the s3: CreateAccessPoint action only if the s3 AccessPointNetworkOrigin condition key evaluates to VPC.
Answers
C.
Use AWS CloudFormation StackSets to create a new 1AM policy in each AVVS account that allows the s3: CreateAccessPoint action only if the s3 AccessPointNetworkOrigin condition key evaluates to VPC.
D.
Set the S3 bucket policy to deny the s3: CreateAccessPoint action unless the s3 AccessPointNetworkOrigin condition key evaluates to VPC.
Answers
D.
Set the S3 bucket policy to deny the s3: CreateAccessPoint action unless the s3 AccessPointNetworkOrigin condition key evaluates to VPC.
Suggested answer: B

Explanation:

https://aws.amazon.com/s3/features/access-points/

https://aws.amazon.com/blogs/storage/managing-amazon-s3-access-with-vpc-endpoints-and-s3-access-points/

asked 16/09/2024
Lazar Marinovic
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first