SAP-C02 Exam Question 31

Question:
A company uses IAM Identity Center for data scientist access. Each user should be able to accessonly their own datain an S3 bucket. The company also needs to generatemonthly access reportsper user.
Options:
  • SAP-C02 Exam Question 32

    A company is updating an application that customers use to make online orders. The number of attacks on the application by bad actors has increased recently.
    The company will host the updated application on an Amazon Elastic Container Service (Amazon ECS) cluster. The company will use Amazon DynamoDB to store application data. A public Application Load Balancer (ALB) will provide end users with access to the application. The company must prevent prevent attacks and ensure business continuity with minimal service interruptions during an ongoing attack.
    Which combination of steps will meet these requirements MOST cost-effectively? (Select TWO.)
  • SAP-C02 Exam Question 33

    A company with several AWS accounts is using AWS Organizations and service control policies (SCPs). An Administrator created the following SCP and has attached it to an organizational unit (OU) that contains AWS account 1111-1111-1111:

    Developers working in account 1111-1111-1111 complain that they cannot create Amazon S3 buckets. How should the Administrator address this problem?
  • SAP-C02 Exam Question 34

    A company is currently in the design phase of an application that will need an RPO of less than 5 minutes and an RTO of less than 10 minutes. The solutions architecture team is forecasting that the database will store approximately 10 TB of data. As part of the design, they are looking for a database solution that will provide the company with the ability to fail over to a secondary Region.
    Which solution will meet these business requirements at the LOWEST cost?
  • SAP-C02 Exam Question 35

    A company has an organization that has many AWS accounts in AWS Organizations. A solutions architect must improve how the company manages common security group rules for the AWS accounts in the organization.
    The company has a common set of IP CIDR ranges in an allow list in each AWS account to allow access to and from the company's on-premises network.
    Developers within each account are responsible for adding new IP CIDR ranges to their security groups. The security team has its own AWS account. Currently, the security team notifies the owners of the other AWS accounts when changes are made to the allow list.
    The solutions architect must design a solution that distributes the common set of CIDR ranges across all accounts.
    Which solution meets these requirements with the LEAST amount of operational overhead?