An organization has launched 5 instances: 2 for production and 3 for testing. The organization wants a particular group of IAM users to access only the test instances and not the production ones. They want to deploy the instances in various locations based on the factors that will change from time to time, especially in the test group. They expect instances will often need to be churned, i.e. deleted and replaced, especially in the testing group. This means the five instances they have created now will soon be replaced by a different set of five instances. The members of each group, produc-tion and testing, will not change in the foreseeable future. Given the situation, what choice below is the most efficient and time-saving strategy to define the IAM policy?
A) By creating an IAM policy with a condition that allows access to only small instances
B) By defining the IAM policy that allows access based on the instance ID
C) By launching the test and production instances in separate regions and allowing region wise ac-cess to the group
D) By defining the tags on the test and production team members IAM user IDs, and adding a con-dition to the IAM policy that allows access to specific tags
Correct Answer:
Verified
Q596: Amazon RDS provides Amazon CloudWatch metrics for
Q597: Amazon CloudFront is a _.
A) persistent block
Q598: Security groups in Amazon VPC _.
A) control
Q599: Which of the following statements is NOT
Q600: A user has set the Alarm for
Q602: A user is planning to schedule a
Q603: A company wants to review the security
Q604: ABC (with AWS account ID 111122223333) has
Q605: An IAM user has two conflicting policies
Q606: What does the Server-side encryption provide in
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents