ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 85 - BDS-C00 discussion

Report
Export

An organization is designing a public web application and has a requirement that states all application users must be centrally authenticated before any operations are permitted. The organization will need to create a user table with fast data lookup for the application in which a user can read only his or her own data. All users already have an account with amazon.com. How can these requirements be met?

A.
Create an Amazon RDS Aurora table, with Amazon_ID as the primary key. The application uses amazon.com web identity federation to get a token that isused to assume an IAM role from AWS STS. Use IAM database authentication byusing the rds:db-tag IAM authentication policy and GRANT Amazon RDS row-level read permission per user.
Answers
A.
Create an Amazon RDS Aurora table, with Amazon_ID as the primary key. The application uses amazon.com web identity federation to get a token that isused to assume an IAM role from AWS STS. Use IAM database authentication byusing the rds:db-tag IAM authentication policy and GRANT Amazon RDS row-level read permission per user.
B.
Create an Amazon RDS Aurora table, with Amazon_ID as the primary key for each user. The application uses amazon.com web identity federation to get atoken that is used to assume an IAM role. Use IAM database authentication byusing rds:db-tag IAM authentication policy and GRANT Amazon RDS row-level read permission per user.
Answers
B.
Create an Amazon RDS Aurora table, with Amazon_ID as the primary key for each user. The application uses amazon.com web identity federation to get atoken that is used to assume an IAM role. Use IAM database authentication byusing rds:db-tag IAM authentication policy and GRANT Amazon RDS row-level read permission per user.
C.
Create an Amazon DynamoDB table, with Amazon_ID as the partition key. The application uses amazon.com web identity federation to get a token that isused to assume an IAM role from AWS STS in the Role, use IAM condition context key dynamodb:LeadingKeys with IAM substitution variables $ {www.amazon.com:user_id} and allow the required DynamoDB API operations in IAM JSON policy Action element for reading the records.
Answers
C.
Create an Amazon DynamoDB table, with Amazon_ID as the partition key. The application uses amazon.com web identity federation to get a token that isused to assume an IAM role from AWS STS in the Role, use IAM condition context key dynamodb:LeadingKeys with IAM substitution variables $ {www.amazon.com:user_id} and allow the required DynamoDB API operations in IAM JSON policy Action element for reading the records.
D.
Create an Amazon DynamoDB table, with Amazon_ID as the partition key. The application uses amazon.com web identity federation to assume an IAM rolefrom AWS STS in the Role, use IAM condition context key dynamodb:LeadingKeys with IAM substitution variables $ {www.amazon.com:user_id} and allow the required DynamoDB API operations in IAM JSON policy Action element for reading the records.
Answers
D.
Create an Amazon DynamoDB table, with Amazon_ID as the partition key. The application uses amazon.com web identity federation to assume an IAM rolefrom AWS STS in the Role, use IAM condition context key dynamodb:LeadingKeys with IAM substitution variables $ {www.amazon.com:user_id} and allow the required DynamoDB API operations in IAM JSON policy Action element for reading the records.
Suggested answer: C

Explanation:


asked 16/09/2024
Enrique Jose Lopez Bolivar
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first