Question 1 of 30
In a multi-account AWS environment, a company has implemented AWS Identity and Access Management (IAM) to manage user permissions across different accounts. The security team needs to ensure that developers can access specific resources in the production account without granting them full administrative privileges. They decide to create a role that allows developers to assume it when they need access. What is the most effective way to implement this role while ensuring that the principle of least privilege is maintained?
Create an IAM role in the production account with permissions limited to the specific resources needed by developers and allow developers from the development account to assume this role using a trust policy.
Create an IAM user for each developer in the production account with full access to all resources to simplify management.
Create a group in the production account that includes all developers and assign it full administrative permissions to ensure they can manage resources as needed.
Create a role in the development account that allows developers to manage resources in the production account without any restrictions.

Preparing for Amazon SOA-C02 AWS Certified SysOps Administrator – Associate (SOA-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free