AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company uses AWS Organizations to manage a multi-account environment. A dedicated Security account (111111111111) is used by the central security team to conduct audits. This team needs read-only access to audit logs stored in hundreds of Amazon S3 buckets across multiple member accounts (e.g., Production account 999999999999, Development account 888888888888). The solution must be scalable, centrally manageable, and adhere to the principle of least privilege. Which approach is the most effective and secure for granting this cross-account access?

  • In the organization's management account, attach a Service Control Policy (SCP) to the relevant Organizational Units (OUs) that explicitly allows the Security account's role to perform read-only actions on S3 buckets in the member accounts.

  • In each member account, create a new set of IAM users for the security team. Attach an IAM policy to these users that grants read-only access to the local S3 buckets.

  • In each member account, modify the S3 bucket policies to grant s3:GetObject and s3:ListBucket permissions directly to the ARN of the security team's IAM role in the Security account (111111111111).

  • In each member account, create an IAM role with a permissions policy granting read-only access to the S3 buckets. Configure the role's trust policy to allow a specific IAM role from the Security account (111111111111) to assume it.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot