Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SCS-C03 Exam - Topic 2 Question 16 Discussion

CloudFormation stack deployments fail for some users due to permission inconsistencies.Which combination of steps will ensure consistent deployments MOST securely? (Select THREE.)
B) Create a service role with cloudformation.amazonaws.com as the principal. and E) Update each stack to use the service role. and F) Allow iam:PassRole to the service role.
A) Create a composite principal service role.
C) Attach scoped policies to the service role.
D) Attach service ARNs in policy resources.

Amazon SCS-C03 Exam - Topic 2 Question 16 Discussion

Actual exam question for Amazon's SCS-C03 exam
Question #: 16
Topic #: 2
[All SCS-C03 Questions]

CloudFormation stack deployments fail for some users due to permission inconsistencies.

Which combination of steps will ensure consistent deployments MOST securely? (Select THREE.)

Show Suggested Answer Hide Answer
Suggested Answer: B, E, F

AWS best practices require CloudFormation to assume a dedicated service role. This ensures consistent permissions regardless of the user. Users must have iam:PassRole permission to pass the role. Updating stacks to use the service role enforces uniform deployment behavior.

Referenced AWS Specialty Documents:

AWS Certified Security -- Specialty Official Study Guide

AWS CloudFormation Service Roles


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel