Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Developer - Associate DVA-C02 Question # 57 Topic 6 Discussion

Amazon Web Services AWS Certified Developer - Associate DVA-C02 Question # 57 Topic 6 Discussion

DVA-C02 Exam Topic 6 Question 57 Discussion:
Question #: 57
Topic #: 6

A developer is building a multi-tenant application using AWS Lambda, Amazon S3, and Amazon DynamoDB. Each S3 object prefix represents a tenant name, and DynamoDB uses the tenant name as the partition key.

The developer must prevent cross-tenant data access during processing.

Which combination of actions will meet this requirement? (Select THREE.)


A.

Create a data access IAM role that allows the sts:TagSession action.


B.

Allow the Lambda execution role to assume the data access role.


C.

Configure IAM policies on the data access role to allow S3 and DynamoDB access only when resource attributes match the tenant session tag.


D.

Create a resource-based policy on DynamoDB based on principal tags.


E.

Create a resource control policy (RCP) for the S3 bucket.


F.

Configure the Lambda function to assume the data access role and pass the tenant name as a session tag.


Get Premium DVA-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.