List of questions
Related questions
Question 362 - SCS-C01 discussion
An employee keeps terminating EC2 instances on the production environment. You've determined the best way to ensure this doesn't happen is to add an extra layer of defense against terminating the instances. What is the best method to ensure the employee does not terminate the production instances? Choose the 2 correct answers from the options below Please select:
A.
Tag the instance with a production-identifying tag and add resource-level permissions to the employee user with an explicit deny on the terminate API call to instances with the production tag.
B.
Tag the instance with a production-identifying tag and modify the employees group to allow only start stop, and reboot API calls and not the terminate instance call.
C.
Modify the IAM policy on the user to require MFA before deleting EC2 instances and disable MFA access to the employee
D.
Modify the IAM policy on the user to require MFA before deleting EC2 instances
Your answer:
0 comments
Sorted by
Leave a comment first