exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 173 discussion

A solutions architect has configured the following IAM policy.

Which action will be allowed by the policy?

  • A. An AWS Lambda function can be deleted from any network.
  • B. An AWS Lambda function can be created from any network.
  • C. An AWS Lambda function can be deleted from the 100.220.0.0/20 network.
  • D. An AWS Lambda function can be deleted from the 220.100.16.0/20 network.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Paitan
Highly Voted 3 years, 9 months ago
There is an explicit deny for the source IP block in the second statement. So only IPs outside that block can delete or create Lambda functions as per the Allow rule in the first statement.So option C is the correct answer.
upvoted 57 times
...
Uzbekistan
Most Recent 1 year, 3 months ago
Selected Answer: C
C is the right option. Only IPs outside of that block can be deleted or created Lambda functions as per the allow rule in the first statement.
upvoted 1 times
...
mfaktas
1 year, 7 months ago
Selected Answer: C
tricky one but for not focused ones :)
upvoted 1 times
...
queen101
2 years, 11 months ago
You need to look for IP outside the denied IP in the 2nd statement. So only option C satisfied that rule. CCCCCCCCCC
upvoted 1 times
...
Alfene
2 years, 11 months ago
Selected Answer: C
C is the answer
upvoted 1 times
...
marklovesaws143
2 years, 11 months ago
Selected Answer: C
CCCCCCCCCCCCC
upvoted 2 times
...
DriVen
3 years, 3 months ago
Nice question
upvoted 4 times
...
saifeddine92
3 years, 4 months ago
Selected Answer: C
C is the correct answer
upvoted 1 times
...
fefer92
3 years, 5 months ago
Selected Answer: C
Answer is C
upvoted 1 times
...
prex
3 years, 6 months ago
why c?
upvoted 2 times
...
gargaditya
3 years, 7 months ago
C Always start with Deny Rule first as it preceeds any Allow Rules. This directly eliminates A,B,D.
upvoted 4 times
...
RagnarLodbrok
3 years, 7 months ago
Tricky question... Answer is C
upvoted 1 times
...
ABC1503
3 years, 8 months ago
C is right answer as they have explicitly denied on IP - 220.100.16.0/20. Hence C is correct ans.
upvoted 3 times
...
AWS_Aspirant_007
3 years, 8 months ago
C , No brainer.. only network block which is not restricted from options.
upvoted 2 times
...
Kenisworld666
3 years, 8 months ago
C is rihgt
upvoted 3 times
...
syu31svc
3 years, 8 months ago
C is the answer The condition to not allow delete is that the network is from 220.100.16.0/20
upvoted 3 times
...
KK_uniq
3 years, 8 months ago
For sure C. It is just any other network than mentiuoned
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...