BlackFriday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SCS-C02 Topic 7 Question 30 Discussion

Actual exam question for Amazon's SCS-C02 exam
Question #: 30
Topic #: 7
[All SCS-C02 Questions]

A company has multiple departments. Each department has its own IAM account. All these accounts belong to the same organization in IAM Organizations.

A large .csv file is stored in an Amazon S3 bucket in the sales department's IAM account. The company wants to allow users from the other accounts to access the .csv file's content through the combination of IAM Glue and Amazon Athen

a. However, the company does not want to allow users from the other accounts to access other files in the same folder.

Which solution will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

Whitney
26 days ago
I'm with Billy on this one. Option C is clearly the most precise way to achieve what the company wants. No need to overcomplicate it.
upvoted 0 times
Elli
5 days ago
I agree with you, Option C seems like the best choice here.
upvoted 0 times
...
...
Billy
1 months ago
Ha! Typical corporate bureaucracy, trying to give access to a single file without letting people see anything else. Option C is the only way to surgically target that .csv.
upvoted 0 times
Allene
1 days ago
Definitely, it's the best way to ensure only the specific file is accessible.
upvoted 0 times
...
Belen
4 days ago
True, that seems like the most precise solution to the problem.
upvoted 0 times
...
Hester
20 days ago
Option C) Define an IAM Glue Data Catalog resource policy in IAM Glue to grant cross-account S3 object access to the .csv file.
upvoted 0 times
...
...
Tom
1 months ago
Option B with S3 Select sounds interesting, but I'm not sure if it will give us the granular control we need over the specific .csv file. C definitely seems like the best choice here.
upvoted 0 times
Kattie
7 days ago
D) Grant IAM Glue access to Amazon S3 in a resource-based policy that specifies the organization as the principal.
upvoted 0 times
...
Alpha
11 days ago
I agree, option C seems like the best choice to ensure granular control over the specific .csv file.
upvoted 0 times
...
Raymon
20 days ago
C) Define an IAM Glue Data Catalog resource policy in IAM Glue to grant cross-account S3 object access to the .csv file.
upvoted 0 times
...
Charlette
29 days ago
B) Use S3 Select to restrict access to the .csv file. In IAM Glue Data Catalog, use S3 Select as the source of the IAM Glue database.
upvoted 0 times
...
...
Leonie
1 months ago
I'm not sure, but option B also seems like a valid solution to restrict access to the .csv file using S3 Select.
upvoted 0 times
...
Amie
2 months ago
I think option C is the way to go. Defining an IAM Glue Data Catalog resource policy in IAM Glue to grant cross-account S3 object access to the .csv file seems like the most targeted and secure solution.
upvoted 0 times
Leota
16 days ago
True, option C does seem more focused on granting access to that specific file.
upvoted 0 times
...
Darell
19 days ago
D) Grant IAM Glue access to Amazon S3 in a resource-based policy that specifies the organization as the principal.
upvoted 0 times
...
Simona
21 days ago
A) Apply a user policy in the other accounts to allow IAM Glue and Athena to access the .csv file.
upvoted 0 times
...
Halina
27 days ago
C) Define an IAM Glue Data Catalog resource policy in IAM Glue to grant cross-account S3 object access to the .csv file.
upvoted 0 times
...
Fidelia
28 days ago
I think option C is more targeted specifically for granting access to the .csv file only.
upvoted 0 times
...
Stephaine
29 days ago
But wouldn't option D also work since it specifies the organization as the principal?
upvoted 0 times
...
Cheryl
1 months ago
I agree, option C seems like the most secure way to grant access to the .csv file.
upvoted 0 times
...
...
Magnolia
2 months ago
I disagree, I believe option D is the way to go as it specifies the organization as the principal for IAM Glue access to Amazon S3.
upvoted 0 times
...
Yolande
2 months ago
I think option C is the best solution because it allows cross-account access to the specific .csv file.
upvoted 0 times
...

Save Cancel