ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A security engineer must ensure that developers can read and write only to Amazon S3 objects belonging to the same project they are assigned. Each developer assumes an IAM role from their AWS account into a shared services account that hosts many project buckets. Which approach best implements attribute-based access control (ABAC) for this requirement?
Attach a service control policy (SCP) to each developer's AWS account that permits access only to buckets whose names start with the project code.
Create individual bucket policies listing the ARNs of developer roles that should have access to each project bucket.
Expose every project bucket through an S3 Access Point restricted to the developers' VPC and use those access points for access control.
Tag the IAM role session with a Project value, tag each S3 bucket with the corresponding Project key, and attach one IAM policy that allows s3:* when aws:PrincipalTag/Project equals aws:ResourceTag/Project.
ABAC in AWS evaluates tags that travel with the principal and tags applied to resources. Tagging the federated role at session time (a principal tag) and tagging each S3 bucket with the same Project key allows a single IAM policy to compare aws:PrincipalTag/Project with aws:ResourceTag/Project. When they match, access is granted; otherwise it is denied. Service control policies, explicit ARN references, or VPC-restricted access points do not provide dynamic tag matching and therefore cannot satisfy the ABAC requirement across all current and future buckets without continual policy updates.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Attribute-Based Access Control (ABAC) in AWS?
Open an interactive chat with Bash
How do principal tags work in AWS IAM?
Open an interactive chat with Bash
Why are Service Control Policies (SCPs) insufficient for ABAC requirements?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .