Question 7 of 19
Single answerCertylQ A company wants to deny a specific federated user named Bob access to an Amazon S3 bucket named DOC- needs to ensure that this bucket policy affects Bob's S3 permissions only. Any other permissions that Bob has must remain intact. Which policy should the company use to meet these requirements?
A"Version":"2012-10-17" "Statement":( "principal":("Aws":"arn:aws:sts::account-id:federaced-user/Bob"), "Effect":"Allow" "Action":"s3:*"
✓B"version":"2012-10-17" "statement":( "principal":{"Aws":"arn:aws:sts::account-id:federated-user/Bob"), "Effect":"Deny", "Action":"s3:*" "Version":"2012-10-17", "statement":( "principal":("Aws":"arn:aws:iam::account-id:user/Bob"), "Effect":"Deny", "Action":"s3:*",
D"Version":"2012-10-17", "statement": "Principal":("Aws":"arn:aws:sts::account-id:assumed-role/Bob/role-session-name") "Effect":"Deny", "Action":"s3:*", -.
✓
Correct Answer: B
"version":"2012-10-17" "statement":( "principal":{"Aws":"arn:aws:sts::account-id:federated-user/Bob"), "Effect":"Deny", "Action":"s3:*" "Version":"2012-10-17", "statement":( "principal":("Aws":"arn:aws:iam::account-id:user/Bob"), "Effect":"Deny", "Action":"s3:*",
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of AWS certification topics.