🔥 40% Off Crucial Exams Memberships — This Week Only

3 days, 8 hours remaining!

AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A development team runs an application on Amazon EC2 instances in Account A. The application must upload daily log files to a private Amazon S3 bucket that is owned by Account B. Security mandates removal of all long-term credentials on the instances and wants access restricted only to writing objects to that specific bucket. Which solution meets these requirements while following AWS IAM best practices?

  • Attach the AmazonS3FullAccess managed policy to the existing EC2 instance profile in Account A and add a bucket policy in Account B that grants the role permission to write objects.

  • Create an IAM user in Account B with programmatic access, store the user's access keys in AWS Systems Manager Parameter Store, and have the EC2 instances read the keys at runtime.

  • Enable S3 cross-region replication from a new bucket in Account A to the target bucket in Account B so logs are copied automatically without additional IAM configuration.

  • In Account B, create an IAM role that allows s3:PutObject only on the log bucket and trusts Account A. Allow the EC2 instance profile in Account A to assume this role with STS, and have the application use the temporary credentials to upload logs.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot