ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 258 - SOA-C02 discussion

Report
Export

A company's application currently uses an IAM role that allows all access to all AWS services. A SysOps administrator must ensure that the company's IAM policies allow only the permissions that the application requires.

How can the SysOps administrator create a policy to meet this requirement?

A.
Turn on AWS CloudTrail. Generate a policy by using AWS Security Hub.
Answers
A.
Turn on AWS CloudTrail. Generate a policy by using AWS Security Hub.
B.
Turn on Amazon EventBridge (Amazon CloudWatch Events). Generate a policy by using AWS Identity and Access Management Access Analyzer.
Answers
B.
Turn on Amazon EventBridge (Amazon CloudWatch Events). Generate a policy by using AWS Identity and Access Management Access Analyzer.
C.
Use the AWS CLI to run the get-generated-policy command in AWS Identity and Access Management Access Analyzer.
Answers
C.
Use the AWS CLI to run the get-generated-policy command in AWS Identity and Access Management Access Analyzer.
D.
Turn on AWS CloudTrail. Generate a policy by using AWS Identity and Access Management Access Analyzer.
Answers
D.
Turn on AWS CloudTrail. Generate a policy by using AWS Identity and Access Management Access Analyzer.
Suggested answer: D

Explanation:

Generate a policy by using AWS Identity and Access Management Access Analyzer. AWS CloudTrail is a service that records all API calls made on your account. You can use this data to generate a policy with AWS Identity and Access Management Access Analyzer that only allows the permissions that the application requires. This will ensure that the application only has the necessary permissions and will protect the company from any unauthorized access.

https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html#what-is-accessanalyzer-policy-generation

asked 16/09/2024
Paul Shortt
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first