Q433. A company is using AWS Organizations to manage 15 AWS accounts. A solutions architect wants to run advanced analytics on the company's cloud expenditures. The cost data must be gathered and made available from an analytic

欢迎免费使用小程序搜题/刷题/查看解析,提升学历,成考自考报名,论文代写、论文查重请加客服微信skr-web


Q433. A company is using AWS Organizations to manage 15 AWS accounts. A solutions architect wants to run advanced analytics on the company's cloud expenditures. The cost data must be gathered and made available from an analytics account. The analytics application runs in a VPC and must receive the raw cost data each night to run the analytics.The solution architect has decided to use the Cost Explorer API to fetch the raw data and store the data in Amazon S3 in Json format.Access to the raw cost data must be restricted to the analytics application. The solution architect has already created an AWS Lambda function
To collect data by the using the Cost Explorer API. Which additional actions should the solutions architect take to meet these requirements?

A.Create an IAM role in the Organizations master account with permissions to use the Cost Explorer API and establish trust between the role and the analytics account.Update the Lambda function role and add sts AssumeRole permissions.Assume the role in the master account from the Lambda function code by using the AWS security Token Service (AWS STS) AssumeRole API call.Create a gateway-endpoint for Amazon S3 in the analytics VPC.Create an S3 buck t policy that allows access only from S3 endpoint.
B.Create an IAM role in the analytics account with permissions to use the Cost Explorer API.Update the Lambda function and assign the new role.Create a gateway endpoint for Amazon S3 in the analytics VPC.Create an S3 bucket policy that allows access from the analytics VPC by using the aws SourceVPC condition
C.Create an IAM role in the Organizations master account with permissions to use the Cost Explorer API and establish trust between the role and the analytics account.Update the Lambda function role and add sts AssumeRole permissions.Assume the role in the master account from the Lambda function code by using the AWS security Token Service (AWS STS) AssumeRole API call.Create an interface endpoint for Amazon S3 in the analytics VPC.Create an S3 bucket policy that allows access only from the analytics VPC private CIDR range by using the aws SourceIp condition.
D.Create an IAM role in the analyti s account with permissions to use the Cost Explorer API.Update the Lambda function and assign the new role.Create an
Interface endpoint for Amazon S3 in the analytics VPC.Create an S3 bucket policy that allows only from the S3 endpoint.
正确答案B
访客
邮箱
网址

通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作


  • 自动写文案
  • 自动写小说
  • 马上扫码让Ai帮你完成工作
通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作

  • 自动写论文
  • 自动写软件
  • 我不是人,但是我比人更聪明,我是强大的Ai
Top