Amazon DOP-C02 Exam - Topic 1 Question 2 Discussion
A company is using an AWS CodeBuild project to build and package an application. The packages are copied to a shared Amazon S3 bucket before being deployed across multiple AWS accounts.The buildspec.yml file contains the following:The DevOps engineer has noticed that anybody with an AWS account is able to download the artifacts.What steps should the DevOps engineer take to stop this?
D) Modify the post_build command to remove --acl authenticated-read and configure a bucket policy that allows read access to the relevant AWS accounts only.
A) Modify the post_build command to use --acl public-read and configure a bucket policy that grants read access to the relevant AWS accounts only.
B) Configure a default ACL for the S3 bucket that defines the set of authenticated users as the relevant AWS accounts only and grants read-only access.
C) Create an S3 bucket policy that grants read access to the relevant AWS accounts and denies read access to the principal ''*''.
Emeline
7 months agoAshleigh
7 months agoDylan
7 months agoMargery
8 months agoVashti
8 months agoAndra
8 months agoHubert
8 months agoVanda
8 months agoMari
8 months agoHana
8 months agoTanja
8 months agoMyrtie
8 months ago