A company has application logs from AWS accounts in an organization in AWS Organizations. A security engineer is copying these logs to a centralized Amazon S3 bucket in the security team’s AWS account.
Each of the company’s applications is in its own AWS account. Logs are encrypted and pushed into S3 buckets that are associated with each account.
The security engineer deploys an AWS Lambda function into each account to copy the relevant log files to the centralized S3 bucket. The Lambda function can copy the log files in the centralized S3 bucket.
The Lambda function’s IAM execution role policy from the security team’s AWS account is the following:
The centralized S3 bucket policy is the following:
The security engineer needs to remove excess permissions while ensuring the functionality of the solution.
Which changes to the policies meet these requirements? (Choose two.)
Toptip
2 years agoPatrickLi
2 years, 4 months agoappashu
2 years, 5 months agoryogoku
2 years, 5 months agoUn1c0rn
2 years, 6 months agoryogoku
2 years, 5 months agosecdaddy
2 years, 5 months agoBalki
2 years, 6 months agoIsaias
2 years, 6 months agoIsaias
2 years, 6 months agotainh
2 years, 6 months agoGreen53
1 year, 11 months agotryks
2 years, 6 months agolandsamboni
2 years, 6 months agolandsamboni
2 years, 6 months agoselim507
2 years, 4 months ago