Examtopics

AWS Certified Security - Specialty
  • Topic 1 Question 98

    A security engineer is troubleshooting an AWS Lambda function that is named MyLambdaFunction. The function is encountering an error when the function attempts to read the objects in an Amazon S3 bucket that is named DOC-EXAMPLE-BUCKET. The S3 bucket has the following bucket policy:

    Which change should the security engineer make to the policy to ensure that the Lambda function can read the bucket objects?

    • Remove the Condition element. Change the Principal element to the following:

    • Change the Action element to the following:

    • Change the Resource element to "arn:aws:s3:::DOC-EXAMPLE- BUCKET/*''.

    • Change the Resource element to "arn:aws:lambda:::function:MyLambdaFunction". Change the Principal element to the following:


    シャッフルモード