exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 246 discussion

A company needs to create and manage multiple AWS accounts for a number of departments from a central location. The security team requires read-only access to all accounts from its own AWS account. The company is using AWS Organizations and created an account for the security team.

How should a solutions architect meet these requirements?

  • A. Use the OrganizationAccountAccessRole IAM role to create a new IAM policy with read-only access in each member account. Establish a trust relationship between the IAM policy in each member account and the security account. Ask the security team to use the IAM policy to gain access.
  • B. Use the OrganizationAccountAccessRole IAM role to create a new IAM role with read-only access in each member account. Establish a trust relationship between the IAM role in each member account and the security account. Ask the security team to use the IAM role to gain access.
  • C. Ask the security team to use AWS Security Token Service (AWS STS) to call the AssumeRole API for the OrganizationAccountAccessRole IAM role in the management account from the security account. Use the generated temporary credentials to gain access.
  • D. Ask the security team to use AWS Security Token Service (AWS STS) to call the AssumeRole API for the OrganizationAccountAccessRole IAM role in the member account from the security account. Use the generated temporary credentials to gain access.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bhanus
Highly Voted 1 year, 10 months ago
Selected Answer: B
B is right A is incorrect as you CANNOT establish a trust relationship between the IAM policy and account C and D does NOT talk about readonly access
upvoted 7 times
...
Christina666
Highly Voted 1 year, 10 months ago
Selected Answer: B
So there is 3 parts, security account, member account, org account Goal: Security account-> member account In org account, use org crossAccountAccessRole-> create ReadOnlyRole in member account Build trust: security account & member account Security account assume member account ReadOnlyRole
upvoted 5 times
...
albert_kuo
Most Recent 1 month, 4 weeks ago
Selected Answer: B
D is incorrect. OrganizationAccountAccessRole will have AdministratorAccess privileage.
upvoted 1 times
...
duriselvan
1 year, 4 months ago
D Ans D. STS AssumeRole with OrganizationAccountAccessRole in Member Account: Pros: Follows best practices for cross-account access using temporary credentials. Minimizes complexity by leveraging the pre-existing OrganizationAccountAccessRole. Cons: Security team needs access to each member account to assume the role. Therefore, option D, using AWS STS to call the AssumeRole API for the OrganizationAccountAccessRole in each member account from the security account, is the most secure and efficient solution. This approach leverages existing IAM roles, minimizes configuration overhead, and adheres to best practices for cross-account access using temporary credentials.
upvoted 1 times
helloworldabc
8 months, 1 week ago
just B
upvoted 1 times
...
0c118eb
1 year, 4 months ago
OrganizationAccountAccessRole by default has AdministratorAccess IAM policy attached. The security team should only get Read Only. Best practice for accounts within an organization is B.
upvoted 3 times
...
...
career360guru
1 year, 5 months ago
Selected Answer: B
Option B
upvoted 1 times
...
ggrodskiy
1 year, 9 months ago
Correct B.
upvoted 1 times
...
NikkyDicky
1 year, 10 months ago
Selected Answer: B
its a b
upvoted 2 times
...
SmileyCloud
1 year, 10 months ago
Selected Answer: B
B - You need a role.
upvoted 1 times
...
easytoo
1 year, 10 months ago
b-b-b-b-b-b-b
upvoted 1 times
...
SkyZeroZx
1 year, 10 months ago
Selected Answer: B
B is classic usage of Cross Account Role
upvoted 1 times
...
Jackhemo
1 year, 10 months ago
oh labiba is 'B' To meet the requirements, a solutions architect should choose option B. Use the OrganizationAccountAccessRole IAM role to create a new IAM role with read-only access in each member account. Establish a trust relationship between the IAM role in each member account and the security account. Ask the security team to use the IAM role to gain access. By using the OrganizationAccountAccessRole IAM role, the solutions architect can create a new IAM role with read-only access in each member account. This allows the security team to have read-only access to all accounts from their own AWS account. The trust relationship between the IAM role in each member account and the security account ensures that the security team can assume the IAM role and access the necessary resources.
upvoted 2 times
...
PhuocT
1 year, 10 months ago
B is the answer
upvoted 1 times
...
gd1
1 year, 10 months ago
Selected Answer: B
GPT: This approach aligns with the AWS best practice of using IAM roles to delegate permissions across AWS accounts. The OrganizationAccountAccessRole is a role that is automatically created when you create a new account in an organization. This role can be assumed by the master account, but it can also be assumed by other accounts if a trust relationship is established.
upvoted 3 times
...
Alabi
1 year, 10 months ago
Selected Answer: B
Option B suggests using the OrganizationAccountAccessRole IAM role to create a new IAM role in each member account. This IAM role will have read-only access permissions. By establishing a trust relationship between the IAM role in each member account and the security account, the security team's AWS account is granted access to the member accounts.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago