QuestionQ4

Security and Compliance

A CloudOps engineer needs to create an IAM policy for a developer who requires access to particular AWS services. Based on these requirements, the CloudOps engineer creates the following policy:

Question Image

Which actions are allowed by this policy?

Choose two
Explanation

The policy allows all Elastic Load Balancing actions through elasticloadbalancing:*, which includes DescribeLoadBalancers, and all AWS Lambda actions through lambda:*, which includes InvokeFunction. It does not allow Storage Gateway creation, IAM role creation, or SQS queue deletion because those actions do not match the permitted action patterns.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!