A SysOps Administrator implemented the following bucket policy to allow only the corporate IP address range of 54.240.143.0/24 to access objects in an Amazon S3 bucket. Some employees are reporting that they are able to access the S3 bucket from IP addresses outside the corporate IP address range. How can the Administrator address this issue?
A) Modify the Condition operator to include both NotIpAddress and IpAddress to prevent unauthorized access to the S3 bucket. Modify the Condition operator to include both NotIpAddress and IpAddress to prevent unauthorized access to the S3 bucket.
B) Modify the Condition element from the IAM policy to aws:StringEquals instead of aws:SourceIp . element from the IAM policy to aws:StringEquals instead of aws:SourceIp .
C) Modify the IAM policy instead of the bucket policy to restrict users from accessing the bucket based on their source IP addresses.
D) Change Effect from Allow to Deny in the second statement of the policy to deny requests not from the source IP range. Change Effect from Allow to Deny in the second statement of the policy to deny requests not from the source IP range.
Correct Answer:
Verified
Q379: The Security team has decided that there
Q380: Which of the following steps are required
Q381: A company stores thousands of non-critical log
Q382: A web application runs on Amazon EC2
Q383: A SysOpsAdministrator is managing a large organization
Q385: A company's web application runs on Amazon
Q386: A company uses multiple accounts for its
Q387: A company is running critical applications on
Q388: What should a SysOps Administrator do to
Q389: A SysOps Administrator is notified that a
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents