Topic 1 Question 171
A company wants to deny a specific federated user named Bob access to an Amazon S3 bucket named DOC-EXAMPLE-BUCKET. The company wants to meet this requirement by using a bucket policy. The company also needs to ensure that this bucket policy affects Bob's S3 permissions only. Any other permissions that Bob has must remain intact.
Which policy should the company use to meet these requirements?
ユーザの投票
コメント(2)
- 👍 6Zek2024/05/14
- 正解だと思う選択肢: B
Answer provided by Claude 3.5 Sonnet: The correct policy to meet the company's requirements is option B. Here's why:
It correctly identifies Bob as a federated user: "arn:aws:sts::account-id:federated-user/Bob" It sets the "Effect" to "Deny", which will prevent Bob from accessing the bucket. It specifies the correct S3 bucket: "arn:aws:s3:::DOC-EXAMPLE-BUCKET" The Action is set to "s3:*", which means it will deny all S3 actions for this specific bucket.
This policy will only affect Bob's S3 permissions for the specified bucket, meeting the requirement that other permissions Bob has must remain intact. It's a bucket policy, so it will only apply to this specific S3 bucket and won't affect Bob's permissions elsewhere. Options A, C, and D are incorrect because: A: This policy allows access instead of denying it. C: This policy uses the wrong ARN format for a federated user. D: This policy targets an assumed role session, not a federated user directly.
👍 1heatblur2024/08/12
シャッフルモード



