FCP_WCS_AD7.4 FCP AWS Cloud Security 7.4 Administrator Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

An organization, operating under strict GDPR and HIPAA compliance mandates, needs to provide an external auditing firm with temporary read-only access to specific S3 buckets containing sensitive customer data across multiple AWS accounts. The auditing firm will utilize temporary IAM roles assumed within these accounts. What is the most effective and secure strategy to enforce this limited access at the organizational level, ensuring that no S3 data modification or exfiltration is possible, and that access is confined strictly to the designated audit buckets?

Implement a Service Control Policy (SCP) at the AWS Organizations Organizational Unit (OU) level that denies all S3 actions by default, and then explicitly allows `s3:GetObject` and `s3:ListBucket` operations only for the specific S3 buckets designated for auditing, while denying all other S3-related actions.
Configure IAM policies within each individual AWS account to grant the auditing firm's assumed roles read-only access to the specified S3 buckets, relying on the principle of least privilege at the account level.
Utilize AWS Config rules to continuously monitor S3 bucket access logs and trigger alerts for any unauthorized access attempts by the auditing firm, without implementing proactive preventative controls.
Create a custom IAM policy that the auditing firm must attach to their temporary roles, which restricts their access to only the necessary S3 buckets and actions, and ensure this policy is disseminated to all relevant accounts.

About the FCP_WCS_AD7.4 FCP AWS Cloud Security 7.4 Administrator Certification

These free practice questions are designed to help you assess your readiness for the FCP_WCS_AD7.4 FCP AWS Cloud Security 7.4 Administrator exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.