AWS SAA-C03 · Question 01 · Domain 1.1: Secure Access
A company stores sensitive documents in an Amazon S3 bucket. The security team requires that only IAM users from a specific AWS account can access the bucket. Which solution is the MOST secure and requires the LEAST operational overhead?
Answer options:
Create an IAM role in the specific account and attach an identity-based policy.
Use an S3 bucket policy that denies access unless the Principal is the specific AWS account ID.
Enable S3 Block Public Access and use S3 Access Points.
Configure a VPC endpoint for S3 and restrict access to the VPC.
65 questions · hints · full answers · grading