exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 609 discussion

Exam question from Amazon's AWS-SysOps
Question #: 609
Topic #: 1
[All AWS-SysOps Questions]

An organization has two AWS accounts: Development and Production. A SysOps Administrator manages access of IAM users to both accounts. Some IAM users in Development should have access to certain resources in Production.
How can this be accomplished?

  • A. Create an IAM role in the Production account with the Development account as a trusted entity and then allow those users from the Development account to assume the Production account IAM role.
  • B. Create a group of IAM users in the Development account, and add Production account service ARNs as resources in the IAM policy.
  • C. Establish a federation between the two accounts using the on-premises Microsoft Active Directory, and allow the Development account to access the Production account through this federation.
  • D. Establish an Amazon Cognito Federated Identity between the two accounts, and allow the Development account to access the Production account through this federation.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
saumenP
Highly Voted 2 years, 7 months ago
A is correct. Ref: https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_cross-account-with-roles.html
upvoted 13 times
...
albert_kuo
Most Recent 10 months ago
Selected Answer: A
By creating an IAM role in the Production account and establishing trust with the Development account, you can define permissions for the IAM role that allow access to specific resources in the Production account. IAM users in the Development account can then assume this IAM role to access the allowed resources.
upvoted 1 times
...
RicardoD
2 years, 6 months ago
A is the answer
upvoted 2 times
...
HVarada
2 years, 6 months ago
Answer is "A".
upvoted 1 times
...
abhishek_m_86
2 years, 6 months ago
A. Create an IAM role in the Production account with the Development account as a trusted entity and then allow those users from the Development account to assume the Production account IAM role.
upvoted 2 times
...
arpana_03
2 years, 6 months ago
A is correct answer
upvoted 2 times
...
jackdryan
2 years, 6 months ago
I'll go with A
upvoted 2 times
...
professor
2 years, 7 months ago
A makes sense
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago