A company is reviewing its 1AM policies. One policy written by the DevOps engineer has been (lagged as too permissive. The policy is used by an AWS Lambda function that issues a stop command to Amazon EC2 instances tagged with Environment: NonProduccion over the weekend. The current policy is:
What changes should the engineer make to achieve a policy ot least permission? (Select THREE.)
A.
B.
C.
D.
E.
F.
The engineer should make the following changes to achieve a policy of least permission:
A:Add a condition to ensure that the principal making the request is an AWS Lambda function. This ensures that only Lambda functions can execute this policy.
B:Narrow down the resources by specifying the ARN of EC2 instances instead of allowing all resources. This ensures that the policy only affects EC2 instances.
D:Add a condition to ensure that this policy only applies to EC2 instances tagged with ''Environment: NonProduction''. This ensures that production environments are not affected by this policy.
AWS Identity and Access Management (IAM) - AWS Documentation
Certified DevOps Engineer - Professional (DOP-C02) Study Guide(page 179)
Viva
10 months agoRoslyn
10 months agoMajor
10 months agoViva
10 months agoRoslyn
10 months agoMajor
11 months agoAntonio
11 months agoShoshana
11 months agoDenae
11 months agoAntonio
11 months agoPamella
1 years agoAmie
1 years agoArthur
1 years agoWillard
1 years agoCarey
1 years agoFrankie
11 months agoDustin
12 months agoOwen
12 months agoCassi
12 months agoShaunna
12 months agoHelaine
12 months agoLyla
1 years agoRonald
1 years agoZena
1 years agoGrover
11 months agoAretha
11 months agoLashaunda
1 years agoLuz
1 years ago