A company is reviewing its IAM policies. One policy written by the DevOps engineer has been flagged as too permissive. The policy is used by an flaws Lambda function that issues a stop command to Amazon EC2 instances tagged with Environment: NonProduction over the weekend. The current policy is: What changes should the engineer make to achieve a policy of least permission? (Choose three.) A. Add the following conditional expression: B. Change “Resource”: “*” to “Resource”: “arn:flaws:ec2:*:*:instance/*” C. Add the following conditional expression: D. Add the following conditional expression: E. Change “Action”: “ec2:*” to “Action”: “ec2:StopInstances” F. Add the following conditional expression: Correct Answer: ADF This question is in DOP-C01 exam For getting AWS DevOps Engineer - Professional Certificate
Please login or Register to submit your answer