{"id":340,"date":"2021-01-08T06:34:41","date_gmt":"2021-01-08T06:34:41","guid":{"rendered":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/aws-certified-sysops-administrator-soa-c01-question333\/"},"modified":"2021-01-08T06:34:41","modified_gmt":"2021-01-08T06:34:41","slug":"aws-certified-sysops-administrator-soa-c01-question333","status":"publish","type":"post","link":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/aws-certified-sysops-administrator-soa-c01-question333\/","title":{"rendered":"AWS Certified SysOps Administrator SOA-C01 &#8211; Question333"},"content":{"rendered":"<div class=\"question\">A security policy allows instances in the Production and Development accounts to write application logs to an Amazon S3 bucket belonging to the Security team\u2019s account. Only the Security team should be allowed to delete logs from the S3 bucket.<br \/>\nUsing the \u201cmyAppRole\u201d EC2 role, the production and development teams report that the application servers are not able to write to the S3 bucket.<br \/>\nWhich changes need to be made to the policy to allow the application logs to be written to the S3 bucket?<br \/>\nProduction Account: 111111111111<br \/>\nDev Account: 222222222222<br \/>\nSecurity Account: 555555555555<br \/>\n<img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full\" src=\"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-content\/uploads\/exam\/_Page_131_Image_0001.jpg\" \/><br \/><strong><br \/>A.<\/strong> Update the Action for the Allow policy from \u201cs3:*\u201d to \u201cs3:PutObject\u201d <br \/><strong>B.<\/strong> Change the order of the statements in the bucket policy, moving the Deny policy above the Allow policy. <br \/><strong>C.<\/strong> Update the Action for the Deny policy from \u201cs3:*\u201d to \u201cs3: Delete*\u201d. <br \/><strong>D.<\/strong> Remove the bucket policy, because the default security behavior will not allow objects to be deleted by non bucket owners.<\/div>\n<p><\/p>\n<style> .hidden-div{ display:none } <\/style>\n<p>\t\t\t\t\t\t\t<button onclick=\"getElementById('hidden-div').style.display = 'block'\"> Show Answer <\/button> <button onclick=\"getElementById('hidden-div').style.display = 'none'\">Hide Answer<\/button><\/p>\n<div class=\"hidden-div\" id=\"hidden-div\"><span style=\"\"><\/p>\n<div class=\"answer\">Correct Answer: <strong>A<\/strong><\/div>\n<p><\/strong><\/span> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>A security policy allows instances in the Production and Development accounts to write application logs to an Amazon S3 bucket belonging to the Security team\u2019s account. Only the Security team should be allowed to delete logs from the S3 bucket. Using the \u201cmyAppRole\u201d EC2 role, the production and development teams report that the application servers [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,336],"class_list":["post-340","post","type-post","status-publish","format-standard","hentry","category-aws-certified-sysops-administrator-soa-c01","tag-aws-certified-sysops-administrator-soa-c01","tag-question-333"],"_links":{"self":[{"href":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-json\/wp\/v2\/posts\/340","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-json\/wp\/v2\/comments?post=340"}],"version-history":[{"count":0,"href":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-json\/wp\/v2\/posts\/340\/revisions"}],"wp:attachment":[{"href":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-json\/wp\/v2\/media?parent=340"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-json\/wp\/v2\/categories?post=340"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/SysOps_Administrator_SOA-C01\/wp-json\/wp\/v2\/tags?post=340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}