exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 333 discussion

Exam question from Amazon's AWS-SysOps
Question #: 333
Topic #: 1
[All AWS-SysOps Questions]

A security policy allows instances in the Production and Development accounts to write application logs to an Amazon S3 bucket belonging to the Security team's account. Only the Security team should be allowed to delete logs from the S3 bucket.
Using the `myAppRole` EC2 role, the production and development teams report that the application servers are not able to write to the S3 bucket.
Which changes need to be made to the policy to allow the application logs to be written to the S3 bucket?
Production Account: 111111111111

Dev Account: 222222222222 -

Security Account: 555555555555 -

  • A. Update the Action for the Allow policy from ג€s3:*ג€ to ג€s3:PutObjectג€
  • B. Change the order of the statements in the bucket policy, moving the Deny policy above the Allow policy.
  • C. Update the Action for the Deny policy from ג€s3:*ג€ to ג€s3: Delete*ג€.
  • D. Remove the bucket policy, because the default security behavior will not allow objects to be deleted by non bucket owners.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
xxxdolorxxx
7 months ago
A seems to be correct.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago