A company must share monthly report files that are uploaded to Amazon S3 with a third party. The third-party user list is dynamic, is distributed, and changes frequently. The least amount of access must be granted to the third party. Administrative overhead must be low for the internal teams who manage the process. How can this be accomplished while providing the LEAST amount of access to the third party?
A) Allow only specified IP addresses to access the S3 buckets which will host files that need to be provided to the third party.
B) Create an IAM role with the appropriate access to the S3 bucket, and grant login permissions to the console for the third party to access the S3 bucket.
C) Create a pre-signed URL that can be distributed by email to the third party, allowing it to download specific S3 filed.
D) Have the third party sign up for an AWS account, and grant it cross-account access to the appropriate S3 bucket in the source account.
Correct Answer:
Verified
Q624: A SysOps Administrator must find a way
Q625: A company currently has a single AWS
Q626: A SysOps Administrator is using AWS CloudFormation
Q627: A company website hosts patches for software
Q628: A mobile application must allow users to
Q630: An organization has two AWS accounts: Development
Q631: A SysOps Administrator wants to automate the
Q632: An organization has hired an external firm
Q633: A photo-sharing site delivers content worldwide from
Q634: An existing, deployed solution uses Amazon EC2
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents