List of questions
Related questions
Question 522 - SCS-C01 discussion
A company has two teams, and each team needs to access its respective Amazon S3 buckets. The company anticipates adding more teams that also will have their own S3 buckets. When the company adds these teams, team members will need the ability to be assigned to multiple teams.
Team members also will need the ability to change teams. Additional S3 buckets can be created or deleted. An 1AM administrator must design a solution to accomplish these goals. The solution also must be scalable and must require the least possible operational overhead. Which solution meets these requirements?
A.
Add users to groups that represent the teams. Create a policy for each team that allows the team to access its respective S3 buckets only. Attach the policy to the corresponding group.
B.
Create an 1AM role for each team. Create a policy for each team that allows the team to access its respective S3 buckets only. Attach the policy to the corresponding role.
C.
Create 1AM roles that are labeled with an access tag value of a team. Create one policy that allows dynamic access to S3 buckets with the same tag. Attach the policy to the 1AM roles. Tag the S3 buckets accordingly.
D.
Implement a role-based access control (RBAC) authorization model. Create the corresponding policies, and attach them to the 1AM users.
Your answer:
0 comments
Sorted by
Leave a comment first