exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 845 discussion

Exam question from Amazon's AWS-SysOps
Question #: 845
Topic #: 1
[All AWS-SysOps Questions]

A SysOps Administrator needs to control access to groups of Amazon EC2 instances using AWS Systems Manager Session Manager. Specific tags on the EC2 instances have already been added.
Which additional actions should the Administrator take to control access? (Choose two.)

  • A. Attach an IAM policy to the users or groups that require access to the EC2 instances.
  • B. Attach an IAM role to control access to the EC2 instances.
  • C. Create a placement group for the EC2 instances and add a specific tag.
  • D. Create a service account and attach it to the EC2 instances that need to be controlled.
  • E. Create an IAM policy that grants access to any EC2 instances with a tag specified in the Condition element.
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️
Reference:
https://aws.amazon.com/premiumsupport/knowledge-center/iam-ec2-resource-tags/

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
task_7
8 months, 4 weeks ago
Selected Answer: BE
Drey 1 year, 4 months ago B. best practise: use the IAM Role E. for the tags
upvoted 1 times
...
waterzhong
1 year, 4 months ago
B,E should be better.
upvoted 1 times
...
Cyril_the_Squirl
2 years ago
B & E are correct. By default AWS ssm session manager doesn’t have permission to manage instances, you must first create Iam role with ssm privileges such as AWSEC2RoleforSSM which already has all the rights you need, then attach this to your instance. Your admin user must of course also have the appropriate rights from iam, either directly or through a group membership.
upvoted 2 times
...
TroyMcLure
2 years ago
Correct Answer: A & E "B" is not clear about what the Role would be attached to. While "A" is complete about that, according to: https://docs.aws.amazon.com/IAM/latest/UserGuide/access_iam-tags.html "You can attach this policy to the IAM users in your account. If a user named richard-roe attempts to start an Amazon EC2 instance, the instance must be tagged Owner=richard-roe or owner=richard-roe. Otherwise he will be denied access. The tag key Owner matches both Owner and owner because condition key names are not case-sensitive."
upvoted 3 times
...
RicardoD
2 years ago
A | E are the answers
upvoted 1 times
...
chewingice
2 years ago
A & E https://docs.aws.amazon.com/IAM/latest/UserGuide/access_iam-tags.html
upvoted 1 times
...
Drey
2 years, 1 month ago
B. best practise: use the IAM Role E. for the tags
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago