Q439. A company needs to create and manage multiple AWS accounts for a number of departments from a central location.The security team requires read- only access to all accounts from its own AWS account. The company is using AW

欢迎免费使用小程序搜题/刷题/查看解析,提升学历,成考自考报名,论文代写、论文查重请加客服微信skr-web


Q439. A company needs to create and manage multiple AWS accounts for a number of departments from a central location.The security team requires read- only access to all accounts from its own AWS account. The company is using AWS Organizations and created an account for the security team. How should a solutions architect meet these requirements?

A.Use the OrganizationAccountAceessRole IAM role to create a new IAM policy with read-only access in each member account.Establish a trust relationship between the IAM policy in each member account and the security account.Ask the security team to use the IAM policy to gain access.
B.Use the OrganizationAccountAccessRole IAM role to create a new IAM role- win read only access in each member account.Establish a trust relationship between the IAM role in each member account and the security account.Ask the security team to use the IAM role to gain access.
C.Ask the security team to use AWS Security Token Service (AWS STS) to call the AssumeRole API for the OrganizationAccountAccessRole IAM role in the master account from the security account.Use the generated temporary credentials to gain access.Ask the security team to use AWS Security Token Service (AWS STS) to call the AssumeRole API for the
D.OrganizationAccountAccessRole IAM role in the member account from the security account.Use the generated temporary credentials to gain access
正确答案D
访客
邮箱
网址

通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作


  • 自动写文案
  • 自动写小说
  • 马上扫码让Ai帮你完成工作
通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作

  • 自动写论文
  • 自动写软件
  • 我不是人,但是我比人更聪明,我是强大的Ai
Top