New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 120 Topic 13 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 120 Topic 13 Discussion

SCS-C02 Exam Topic 13 Question 120 Discussion:
Question #: 120
Topic #: 13

A company has an organization in AWS Organizations that includes dedicated accounts for each of its business units. The company is collecting all AWS CloudTrail logs from the accounts in a single Amazon S3bucket in the top-level account. The company's IT governance team has access to the top-level account. A security engineer needs to allow each business unit to access its own CloudTrail logs.

The security engineer creates an IAM role in the top-level account for each of the other accounts. For each role the security engineer creates an IAM policy to allow read-only permissions to objects in the S3 bucket with the prefix of the respective logs.

Which action must the security engineer take in each business unit account to allow an IAM user in that account to read the logs?


A.

Attach a policy to the IAM user to allow the user to assume the role that was created in the top-level account. Specify the role's ARN in the policy.


B.

Create an SCP that grants permissions to the top-level account.


C.

Use the root account of the business unit account to assume the role that was created in the top-level account. Specify the role'sARNin the policy.


D.

Forward the credentials of the IAM role in the top-level account to the IAM user in the business unit account.


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.