exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 231 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 231
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company is setting up products to deploy in AWS Service Catalog. Management is concerned that when users launch products, elevated IAM privileges will be required to create resources.
How should the company mitigate this concern?

  • A. Add a template constraint to each product in the portfolio.
  • B. Add a launch constraint to each product in the portfolio.
  • C. Define resource update constraints for each product in the portfolio.
  • D. Update the AWS CloudFormation template backing the product to include a service role configuration.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ChinkSantana
Highly Voted 3 years, 9 months ago
B is good. Launch constraints allow an AWS Service Catalog end user to launch an AWS Service Catalog product without requiring elevated permissions to AWS resources.
upvoted 12 times
DahMac
3 years, 8 months ago
https://docs.aws.amazon.com/servicecatalog/latest/adminguide/constraints-launch.html Launch constraints apply to products in the portfolio (product-portfolio association). Launch constraints do not apply at the portfolio level or to a product across all portfolios. To associate a launch constraint with all products in a portfolio, you must apply the launch constraint to each product individually.
upvoted 1 times
...
...
Raphaello
Most Recent 1 year, 4 months ago
Selected Answer: B
B is correct. Apply launch constraints to each product in the portfolio. Launch constraint specifies the IAM role that AWS Service Catalog assumes when an end user launches, updates, or terminates a product.
upvoted 1 times
...
pal40sg
2 years, 1 month ago
Selected Answer: B
Option B, "Add a launch constraint to each product in the portfolio," is the correct choice. A launch constraint allows administrators to define restrictions on which AWS Identity and Access Management (IAM) roles or users can launch a particular product. By applying launch constraints, the company can ensure that only users with the necessary permissions can provision resources associated with the product. This helps prevent unauthorized access and reduces the risk of accidental or intentional misconfiguration.
upvoted 2 times
...
Smartphone
2 years, 5 months ago
Answer is B "Launch constraints allow an AWS Service Catalog end user to launch an AWS Service Catalog product without requiring elevated permissions to AWS resources." https://aws.amazon.com/blogs/mt/how-to-launch-secure-and-governed-aws-resources-with-aws-cloudformation-and-aws-service-catalog/
upvoted 1 times
...
sapien45
2 years, 10 months ago
Selected Answer: B
A launch constraint specifies the AWS Identity and Access Management (IAM) role that AWS Service Catalog assumes when an end user launches a product. Without a launch constraint, end users must launch and manage products using their own IAM credentials.
upvoted 2 times
...
hk436
3 years, 8 months ago
B is my answer.
upvoted 1 times
...
kiev
3 years, 8 months ago
B for me as well
upvoted 1 times
...
cldy
3 years, 9 months ago
B. Launch constraint
upvoted 2 times
...
DayQuil
3 years, 9 months ago
B is correct.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...