A company is reviewing its 1AM policies. One policy written by the DevOps engineer has been (lagged as too permissive. The policy is used by an AWS Lambda function that issues a stop command to Amazon EC2 instances tagged with Environment: NonProduccion over the weekend. The current policy is:

What changes should the engineer make to achieve a policy ot least permission? (Select THREE.)
A.

B.

C.

D.

E.

F.

The engineer should make the following changes to achieve a policy of least permission:
A:Add a condition to ensure that the principal making the request is an AWS Lambda function. This ensures that only Lambda functions can execute this policy.
B:Narrow down the resources by specifying the ARN of EC2 instances instead of allowing all resources. This ensures that the policy only affects EC2 instances.
D:Add a condition to ensure that this policy only applies to EC2 instances tagged with ''Environment: NonProduction''. This ensures that production environments are not affected by this policy.
AWS Identity and Access Management (IAM) - AWS Documentation
Certified DevOps Engineer - Professional (DOP-C02) Study Guide(page 179)
Ernie
9 months agoAilene
9 months agoRasheeda
10 months agoJannette
10 months agoLettie
10 months agoTennie
10 months agoThora
11 months agoMerilyn
11 months agoMatilda
11 months agoDetra
11 months agoLucy
11 months agoCorrie
11 months agoLeatha
11 months agoRemona
11 months agoSalley
11 months agoJaney
11 months agoLynsey
11 months agoViva
2 years agoRoslyn
2 years agoMajor
2 years agoViva
2 years agoRoslyn
2 years agoMajor
2 years agoAntonio
2 years agoShoshana
2 years agoDenae
2 years agoAntonio
2 years agoPamella
2 years agoAmie
2 years agoArthur
2 years agoWillard
2 years agoCarey
2 years agoFrankie
2 years agoDustin
2 years agoOwen
2 years agoCassi
2 years agoShaunna
2 years agoHelaine
2 years agoLyla
2 years agoRonald
2 years agoZena
2 years agoGrover
2 years agoAretha
2 years agoLashaunda
2 years agoLuz
2 years ago