A company is reviewing its 1AM policies. One policy written by the DevOps engineer has been (lagged as too permissive. The policy is used by an AWS Lambda function that issues a stop command to Amazon EC2 instances tagged with Environment: NonProduccion over the weekend. The current policy is:
What changes should the engineer make to achieve a policy ot least permission? (Select THREE.)
A.
B.
C.
D.
E.
F.
The engineer should make the following changes to achieve a policy of least permission:
A:Add a condition to ensure that the principal making the request is an AWS Lambda function. This ensures that only Lambda functions can execute this policy.
B:Narrow down the resources by specifying the ARN of EC2 instances instead of allowing all resources. This ensures that the policy only affects EC2 instances.
D:Add a condition to ensure that this policy only applies to EC2 instances tagged with ''Environment: NonProduction''. This ensures that production environments are not affected by this policy.
AWS Identity and Access Management (IAM) - AWS Documentation
Certified DevOps Engineer - Professional (DOP-C02) Study Guide(page 179)
Viva
8 months agoRoslyn
8 months agoMajor
8 months agoViva
8 months agoRoslyn
9 months agoMajor
9 months agoAntonio
9 months agoShoshana
9 months agoDenae
10 months agoAntonio
10 months agoPamella
11 months agoAmie
11 months agoArthur
11 months agoWillard
11 months agoCarey
11 months agoFrankie
10 months agoDustin
10 months agoOwen
10 months agoCassi
10 months agoShaunna
10 months agoHelaine
10 months agoLyla
11 months agoRonald
11 months agoZena
11 months agoGrover
9 months agoAretha
10 months agoLashaunda
11 months agoLuz
11 months ago