A Systems Administrator has written the following Amazon S3 bucket policy designed to allow access to an S3 bucket for only an authorized AWS IAM user from the IP address range 10.10.10.0/24:
When trying to download an object from the S3 bucket from 10.10.10.40, the IAM user receives an access denied message. What does the Administrator need to change to grant access to the user?
A) Change the "Resource" from "arn: aws:s3:::Bucket" to "arn:aws:s3:::Bucket/*".
B) Change the "Principal" from "*" to {AWS:"arn:aws:iam: : account-number: user / username"}
C) Change the "Version" from "2012-10-17" to the last revised date of the policy
D) Change the "Action" from ["s3:*"] to ["s3:GetObject", "s3:ListBucket"]
Correct Answer:
Verified
Q41: A Development team has asked for help
Q42: The Security Engineer is managing a traditional
Q43: Some highly sensitive analytics workloads are to
Q44: A Developer who is following AWS best
Q45: A company runs an application on AWS
Q47: A Security Analyst attempted to troubleshoot the
Q48: An organization operates a web application that
Q49: An application has been built with Amazon
Q50: Which of the following is the most
Q51: The Security Engineer has discovered that a
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents