A company is reviewing its 1AM policies. One policy written by the DevOps engineer has been (lagged as too permissive. The policy is used by an AWS Lambda function that issues a stop command to Amazon EC2 instances tagged with Environment: NonProduccion over the weekend. The current policy is:

What changes should the engineer make to achieve a policy ot least permission? (Select THREE.)
A.

B.

C.

D.

E.

F.

The engineer should make the following changes to achieve a policy of least permission:
A:Add a condition to ensure that the principal making the request is an AWS Lambda function. This ensures that only Lambda functions can execute this policy.
B:Narrow down the resources by specifying the ARN of EC2 instances instead of allowing all resources. This ensures that the policy only affects EC2 instances.
D:Add a condition to ensure that this policy only applies to EC2 instances tagged with ''Environment: NonProduction''. This ensures that production environments are not affected by this policy.
AWS Identity and Access Management (IAM) - AWS Documentation
Certified DevOps Engineer - Professional (DOP-C02) Study Guide(page 179)
Ernie
3 months agoAilene
3 months agoRasheeda
3 months agoJannette
4 months agoLettie
4 months agoTennie
4 months agoThora
4 months agoMerilyn
4 months agoMatilda
5 months agoDetra
5 months agoLucy
5 months agoCorrie
5 months agoLeatha
5 months agoRemona
5 months agoSalley
5 months agoJaney
5 months agoLynsey
5 months agoViva
2 years agoRoslyn
2 years agoMajor
2 years agoViva
2 years agoRoslyn
2 years agoMajor
2 years agoAntonio
2 years agoShoshana
2 years agoDenae
2 years agoAntonio
2 years agoPamella
2 years agoAmie
2 years agoArthur
2 years agoWillard
2 years agoCarey
2 years agoFrankie
2 years agoDustin
2 years agoOwen
2 years agoCassi
2 years agoShaunna
2 years agoHelaine
2 years agoLyla
2 years agoRonald
2 years agoZena
2 years agoGrover
2 years agoAretha
2 years agoLashaunda
2 years agoLuz
2 years ago