nerdexam
Amazon

SCS-C02 · Question #410

A security engineer needs to run an AWS CloudFormation script. The CloudFormation script builds AWS infrastructure to support a stack that includes web servers and a MySQL database. The stack has been

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #410. The question stem and answer options stay visible for context.

Submitted by jaden.t· Mar 6, 2026Identity and Access Management

Question

A security engineer needs to run an AWS CloudFormation script. The CloudFormation script builds AWS infrastructure to support a stack that includes web servers and a MySQL database. The stack has been deployed in pre-production environments and is ready for production. The production script must comply with the principle of least privilege. Additionally, separation of duties must exist between the security engineer's IAM account and CloudFormation. Which solution will meet these requirements?

Options

  • AUse IAM Access Analyzer policy generation to generate a policy that allows the CloudFormation
  • BCreate an IAM policy that allows ec2:* and rds:* permissions. Attach the policy to a new IAM role.
  • CUse IAM Access Analyzer policy generation to generate a policy that allows the CloudFormation
  • DCreate an IAM policy that allows ec2:* and rds:* permissions. Attach the policy to a new IAM role.

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IAM Roles#Least Privilege#CloudFormation Security#IAM Access Analyzer
Full SCS-C02 Practice