An application uses Amazon Cognito to manage end users' permissions when directly accessing AWS resources, including Amazon DynamoDB. A new feature request reads as follows: Provide a mechanism to mark customers as suspended pending investigation or suspended permanently. Customers should still be able to log in when suspended, but should not be able to make changes. The priorities are to reduce complexity and avoid potential for future security issues. Which approach will meet these requirements and priorities?
A) Create a new database field "suspended_status" and modify the application logic to validate that field when processing requests.
B) Add suspended customers to second Cognito user pool and update the application login flow to check both user pools.
C) Use Amazon Cognito Sync to push out a "suspension_status" parameter and split the lAM policy into normal users and suspended users.
D) Move suspended customers to a second Cognito group and define an appropriate IAM access policy for the group.
Correct Answer:
Verified
Q116: A company has multiple VPCs in their
Q117: A Developer's laptop was stolen. The laptop
Q118: For compliance reasons, an organization limits the
Q119: A distributed web application is installed across
Q120: A company recently experienced a DDoS attack
Q122: A company had one of its Amazon
Q123: A Security Engineer has discovered that, although
Q124: A Security Engineer is setting up an
Q125: A company has enabled Amazon GuardDuty in
Q126: An organization receives an alert that indicates
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents