🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An AWS security engineer must grant an Amazon ECS task the minimum rights needed to read messages from a single SQS queue and upload objects only to the reports/ prefix of a specific S3 bucket. According to least-privilege authorization principles and to reduce future maintenance overhead, which approach best satisfies the requirement?

  • Add the task execution role to an IAM group that already holds permissions for all company S3 buckets and SQS queues.

  • Create a custom inline IAM policy that specifies only the required SQS and S3 actions on the exact queue ARN and reports/ prefix, then attach it to the ECS task execution role.

  • Configure an S3 bucket policy granting the task execution role full access to the bucket and rely on default permissions to allow SQS access.

  • Attach the AmazonSQSFullAccess and AmazonS3FullAccess AWS managed policies directly to the ECS task execution role.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot