The Security team needs to provide a team of interns with an AWS environment so they can build a serverless video transcoding application. The project will use Amazon S3, AWS Lambda, Amazon API Gateway, Amazon Cognito, Amazon DynamoDB, and Amazon Elastic Transcoder. The interns should be able to create and configure the necessary resources, but they may not have access to create or modify AWS IAM roles. The Solutions Architect creates a policy and attaches it to the interns' group. How should the Security team configure the environment to ensure that the interns are self-sufficient?
A) Create a policy that allows creation of project-related resources only. Create roles with required service permissions, which are assumable by the services.
B) Create a policy that allows creation of all project-related resources, including roles that allow access only to specified resources.
C) Create roles with the required service permissions, which are assumable by the services. Have the interns create and use a bastion host to create the project resources in the project subnet only.
D) Create a policy that allows creation of project-related resources only. Require the interns to raise a request for roles to be created with the Security team. The interns will provide the requirements for the permissions to be set in the role.
Correct Answer:
Verified
Q560: Identify a correct statement about the expiration
Q561: A bank is designing an online customer
Q562: A company currently runs a secure application
Q563: A company is building an AWS landing
Q564: A company has a standard three-tier architecture
Q566: A company is planning the migration of
Q567: A company stores sales transaction data in
Q568: An organization has a write-intensive mobile application
Q569: Which of the following does Amazon DynamoDB
Q570: A large company has many business units.
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents