AWS Certified Developer Associate DVA-C02 Practice Question
To comply with an inter-company collaboration, your team is required to configure a cloud storage resource enabling another organization to have readonly access to specific files. Your task is to determine how to accomplish this without granting unnecessary privileges or altering user management in the other organization. What is the most effective method to establish this level of access control?
Provision individual user accounts for the external entity within your identity management system, assigning full privileges over the storage resource.
Deploy a series of temporary URLs for each file, allowing indefinite access to the resources without restriction.
Create a bucket policy that allows readonly access to the specified files for the external entity's account identifier.
Update the storage resource's ACL to give ownership permissions to the external entity’s account identifier.
A bucket policy is the most suitable option for this scenario because it allows you to grant precise permissions, such as readonly access, to resources in your bucket to another account without creating individual user accounts or sharing security credentials. This method adheres to the principle of least privilege, ensuring you're not granting any more permissions than necessary. The alternatives either grant overly broad permissions, do not cater to cross-account access efficiently, or would require managing credentials directly, which is not advised.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a bucket policy in AWS?
Open an interactive chat with Bash
What does 'readonly access' mean in the context of AWS S3?
Open an interactive chat with Bash
What is the principle of least privilege and why is it important?
Open an interactive chat with Bash
AWS Certified Developer Associate DVA-C02
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access