A company is reviewing its 1AM policies. One policy written by the DevOps engineer has been (lagged as too permissive. The policy is used by an AWS Lambda function that issues a stop command to Amazon EC2 instances tagged with Environment: NonProduccion over the weekend. The current policy is:
What changes should the engineer make to achieve a policy ot least permission? (Select THREE.)
A.
B.
C.
D.
E.
F.
The engineer should make the following changes to achieve a policy of least permission:
A:Add a condition to ensure that the principal making the request is an AWS Lambda function. This ensures that only Lambda functions can execute this policy.
B:Narrow down the resources by specifying the ARN of EC2 instances instead of allowing all resources. This ensures that the policy only affects EC2 instances.
D:Add a condition to ensure that this policy only applies to EC2 instances tagged with ''Environment: NonProduction''. This ensures that production environments are not affected by this policy.
AWS Identity and Access Management (IAM) - AWS Documentation
Certified DevOps Engineer - Professional (DOP-C02) Study Guide(page 179)
Viva
5 months agoRoslyn
5 months agoMajor
5 months agoViva
5 months agoRoslyn
5 months agoMajor
6 months agoAntonio
6 months agoShoshana
6 months agoDenae
6 months agoAntonio
6 months agoPamella
7 months agoAmie
7 months agoArthur
7 months agoWillard
7 months agoCarey
7 months agoFrankie
7 months agoDustin
7 months agoOwen
7 months agoCassi
7 months agoShaunna
7 months agoHelaine
7 months agoLyla
7 months agoRonald
7 months agoZena
7 months agoGrover
6 months agoAretha
6 months agoLashaunda
7 months agoLuz
7 months ago