Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SCS-C01 Topic 7 Question 66 Discussion

Actual exam question for Amazon's SCS-C01 exam
Question #: 66
Topic #: 7
[All SCS-C01 Questions]

A Security Administrator is restricting the capabilities of company root user accounts. The company uses IAM Organizations and has enabled it for all feature sets, including consolidated billing. The top-level account is used for billing and administrative purposes, not for operational IAM resource purposes.

How can the Administrator restrict usage of member root user accounts across the organization?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Cammy
8 months ago
Option B is a big no-no. Giving users direct access to the S3 bucket is a security nightmare waiting to happen.
upvoted 0 times
...
Reena
8 months ago
Haha, option D sounds like a lot of extra work. Why bother with CloudFront when you can just use the simple presigned URL approach?
upvoted 0 times
Shawnda
6 months ago
That's true, but using a presigned URL still provides a secure way to grant temporary access without the extra setup of CloudFront.
upvoted 0 times
...
Carmela
7 months ago
But what about option A? Removing access after a set time seems like a good security measure.
upvoted 0 times
...
Kathryn
7 months ago
I agree, using a presigned URL is a simple and secure solution for granting access to S3 objects.
upvoted 0 times
...
Hester
7 months ago
Yeah, I think using a presigned URL is definitely the way to go in this situation.
upvoted 0 times
...
Louvenia
7 months ago
I agree, option C seems like the easiest and most secure way to handle this.
upvoted 0 times
...
Melissa
7 months ago
Option C is definitely the easiest way to go. No need to overcomplicate things with CloudFront.
upvoted 0 times
...
...
Jamal
8 months ago
I think configuring read-only access with a bucket ACL and removing access after a set time is a good security measure too.
upvoted 0 times
...
Phuong
8 months ago
I believe creating an S3 presigned URL is also secure, as it limits the access to a specific time period.
upvoted 0 times
...
Eve
8 months ago
I agree with Quinn. Using CloudFront signed URL adds an extra layer of security.
upvoted 0 times
...
Christiane
9 months ago
I agree, C is the best option. Presigned URLs provide a secure way to grant temporary access without managing IAM policies.
upvoted 0 times
...
Kerrie
9 months ago
Option C seems like the most secure choice. Generating a presigned URL allows you to give temporary access without exposing the S3 bucket directly.
upvoted 0 times
Wayne
7 months ago
D) Create an Amazon CloudFront signed URL. Provide the CloudFront signed URL to the user through the application.
upvoted 0 times
...
Blondell
7 months ago
A) Configure read-only access to the object by using a bucket ACL. Remove the access after a set time has elapsed.
upvoted 0 times
...
Kelvin
7 months ago
C) Create an S3 presigned URL Provide the S3 presigned URL to the user through the application.
upvoted 0 times
...
Zita
7 months ago
D) Create an Amazon CloudFront signed URL. Provide the CloudFront signed URL to the user through the application.
upvoted 0 times
...
Virgilio
8 months ago
A) Configure read-only access to the object by using a bucket ACL. Remove the access after a set time has elapsed.
upvoted 0 times
...
Leonardo
8 months ago
C) Create an S3 presigned URL Provide the S3 presigned URL to the user through the application.
upvoted 0 times
...
...
Quinn
9 months ago
I think the most secure way is to create an Amazon CloudFront signed URL.
upvoted 0 times
...

Save Cancel