SAA-C03 · Question #183
A company stores data for multiple business units in a single Amazon S3 bucket that is in the company's payer AWS account. To maintain data isolation, the business units store data in separate prefixe
Sign in or unlock SAA-C03 to reveal the answer and full explanation for question #183. The question stem and answer options stay visible for context.
Question
A company stores data for multiple business units in a single Amazon S3 bucket that is in the company's payer AWS account. To maintain data isolation, the business units store data in separate prefixes in the S3 bucket by using an S3 bucket policy. The company plans to add a large number of dynamic prefixes. The company does not want to rely on a single S3 bucket policy to manage data access at scale. The company wants to develop a secure access management solution in addition to the bucket policy to enforce prefix-level data isolation. Which solution will meet these requirements?
Options
- AConfigure the S3 bucket policy to deny s3:GetObject permissions for all users. Configure the
- BEnable default encryption on the S3 bucket by using server-side encryption with Amazon S3
- CConfigure resource-based permissions on the S3 bucket by creating an S3 access point for each
- DUse pre-signed URLs to provide access to the S3 bucket.
Unlock SAA-C03 to see the answer
You've previewed enough free SAA-C03 questions. Unlock SAA-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.