Find answers, ask questions, and connect with our
community around the world.

Home Forums AWS AWS Certified Developer Associate I Do not understand the answer to the following question

  • I Do not understand the answer to the following question

  • wail-el-edghiri

    Member
    May 17, 2023 at 9:31 pm

    Hello all,

    I’m new to this forum and would like to get help on the following question from test 1 in the aws associate developer certification set tests

    A company has created a private S3 bucket named tdojo. The Developer IAM role must be granted read access to all objects within this bucket. However, objects stored under the qa folder should be restricted to the QA IAM role only.

    Which S3 bucket policy will effectively implement the principle of least privilege access while satisfying the given requirements?

    I don’t understand why the answer should be granting the developer team access to all the objects in the bucket while in the question it’s stated that the qa object should only be accessible to QA role. Thanks in advance for your help.

  • Carlo-TutorialsDojo

    Administrator
    May 19, 2023 at 12:31 am

    Hello wail-el-edghiri,

    Thanks for your feedback.

    The scenario specifically states two conditions. First, the Developer IAM role needs to have read access to all objects in the bucket. This is just one part of the equation. The second piece is that the QA role should only have access to the ‘qa’ folder. The correct option must address both of these requirements.

    Let me know if this answers your question.

    Regards,

    Carlo @ Tutorials Dojo

Viewing 1 - 2 of 2 replies

Log in to reply.

Original Post
0 of 0 posts June 2018
Now