ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 401 - SCS-C01 discussion

Report
Export

Your company has many AWS accounts defined and all are managed via AWS Organizations. One AWS account has a S3 bucket that has critical dat a. How can we ensure that all the users in the AWS organisation have access to this bucket?

Please select:

A.
Ensure the bucket policy has a condition which involves aws:PrincipalOrglD
Answers
A.
Ensure the bucket policy has a condition which involves aws:PrincipalOrglD
B.
Ensure the bucket policy has a condition which involves aws:AccountNumber
Answers
B.
Ensure the bucket policy has a condition which involves aws:AccountNumber
C.
Ensure the bucket policy has a condition which involves aws:PrincipaliD
Answers
C.
Ensure the bucket policy has a condition which involves aws:PrincipaliD
D.
Ensure the bucket policy has a condition which involves aws:OrglD
Answers
D.
Ensure the bucket policy has a condition which involves aws:OrglD
Suggested answer: A

Explanation:

The AWS Documentation mentions the following

AWS Identity and Access Management (IAM) now makes it easier for you to control access to your AWS resources by using the AWS organization of IAM principals (users and roles). For some services, you grant permissions using resource- based policies to specify the accounts and principals that can access the resource and what actions they can perform on it. Now, you can use a new condition key, aws:PrincipalOrglD, in these policies to require all principals accessing the resource to be from an account in the organization Option B.C and D are invalid because the condition in the bucket policy has to mention aws:PrincipalOrglD For more information on controlling access via Organizations, please refer to the below Link:

https://aws.amazon.com/blogs/security/control-access-to-aws-resources-by-usins-the-awsorganization-of-iam-principal ( The correct answer is: Ensure the bucket policy has a condition which involves aws:PrincipalOrglD Submit your Feedback/Queries to our Experts

asked 16/09/2024
Luigi Trigilio
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first