passdrill
AWS SAA-C03 · S3 & Storage · Card 019/030 medium

Account A owns an S3 bucket. A team in Account B needs to be able to run GetObject and PutObject against a specific prefix in that bucket, using their own IAM role in Account B, without Account A creating any IAM users for Account B's team. Which mechanism directly grants this cross-account access?

  1. An S3 Access Control List (ACL) granting Account B's root user FULL_CONTROL over the bucket
  2. An IAM permissions boundary attached to Account B's role
  3. S3 Object Lock configured in Governance mode on the prefix
  4. A bucket policy on Account A's bucket that names Account B's IAM role ARN as principal and allows the required actions on that prefix
Next card → Shuffle