🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 13 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A DevOps team assigned an IAM role to a fleet of Amazon EC2 instances so an application can store logs in an existing S3 bucket. The role currently uses the AWS-managed policy AmazonS3FullAccess. To meet the organization's least-privilege requirements without disrupting log uploads, which action should the security administrator take?

  • Detach AmazonS3FullAccess and attach an inline policy that allows s3:PutObject (and related write actions) only on the specified bucket ARN.

  • Replace AmazonS3FullAccess with the AWS-managed AmazonS3ReadOnlyAccess policy.

  • Keep AmazonS3FullAccess but add an explicit deny for s3:DeleteObject on all buckets.

  • Move the bucket to a separate AWS account and add a bucket policy that allows the role to perform s3:* on the bucket.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot