🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company runs an analytics platform on AWS. Data Scientists, Data Engineers, and Audit staff each need different levels of access to several Amazon S3 buckets and AWS Glue jobs. To follow the principles of subject-based role-based access control (RBAC) and keep policy administration simple, which approach should the security engineer implement?

  • Apply distinct resource-based policies to every S3 bucket and Glue job that list the ARNs of allowed users for each action.

  • Attach individual identity-based policies directly to each user account so that every user receives only the permissions they personally need.

  • Configure S3 bucket ACLs and Glue resource policies to grant access to specific IAM user ARNs without using groups or roles.

  • Create separate IAM groups (or roles) for Data Scientists, Data Engineers, and Auditors, attach the appropriate permission policies to each group, and add users to the groups.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot