A retail company needs to provide a series of data files to another company, which is its business partner These files are saved in an Amazon S3 bucket under Account A, which belongs to the retail company. The business partner company wants one of its 1AM users. User_DataProcessor. to access the files from its own AWS account (Account B). Which combination of steps must the companies take so that User_DataProcessor can access the S3 bucket successfully? (Select TWO.)
Q: 1
Options
Discussion
Why is anyone picking E here? The scenario only asks for access by User_DataProcessor, not all users in Account B. D looks more precise since it's scoped to that user.
Option C and D. E's a trap because it grants permissions but the bucket policy in C trusts the whole account, so D is enough for just that IAM user. Saw this setup on another practice. Disagree?
Had something like this in a mock test, I picked C and E.
Maybe D , but C could apply if the bucket policy used an explicit Principal for just that one user.
Yeah, C and D here. You need the bucket policy in Account A (C) plus the user policy in Account B (D) for proper cross-account access, pretty sure. E looks similar but isn't scoped right. Agree?
Be respectful. No spam.
Question 1 of 35