PAS-C01 · Question #119
A company is running an SAP HANA database on AWS. The company is running AWS Backint Agent for SAP HANA (AWS Backint agent) on an Amazon EC2 instance. AWS Backint agent is configured to back up to…
The correct answer is B. Assign an IAM role to an EC2 instance. Attach a policy to the IAM role to grant access to the target. An AccessDenied error when AWS Backint Agent attempts to write to or read from an S3 bucket is an IAM permissions issue. The correct AWS-native solution is to attach an IAM role to the EC2 instance running the Backint Agent, with a policy that grants the necessary S3 actions…
Question
A company is running an SAP HANA database on AWS. The company is running AWS Backint Agent for SAP HANA (AWS Backint agent) on an Amazon EC2 instance. AWS Backint agent is configured to back up to an Amazon S3 bucket. The backups are failing with an AccessDenied error in the AWS Backint agent log file. What should an SAP basis administrator do to resolve this error?
Options
- AAssign execute permissions at the operating system level for the AWS Backint agent binary and
- BAssign an IAM role to an EC2 instance. Attach a policy to the IAM role to grant access to the target
- CAssign the correct Region ID for the S3BucketAwsRegion parameter in AWS Backint agent for the
- DAssign the value for the EnableTagging parameter in AWS Backint agent for the SAP HANA
How the community answered
(34 responses)- A3% (1)
- B94% (32)
- D3% (1)
Explanation
An AccessDenied error when AWS Backint Agent attempts to write to or read from an S3 bucket is an IAM permissions issue. The correct AWS-native solution is to attach an IAM role to the EC2 instance running the Backint Agent, with a policy that grants the necessary S3 actions (s3:PutObject, s3:GetObject, s3:ListBucket, etc.) on the target bucket. Using IAM roles (instead of access keys) is the AWS best practice for granting EC2 instances access to AWS services. Option A (OS-level execute permissions) addresses file system permissions, not AWS API authorization. Option C (Region ID parameter) would cause a different error (wrong bucket endpoint), not AccessDenied. Option D (EnableTagging parameter) controls metadata tagging behavior and has no effect on access authorization.
Topics
Community Discussion
No community discussion yet for this question.