CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud administrator is configuring an identity and access management (IAM) policy for a new cloud storage bucket. The policy must grant a specific development team read-only access to a particular folder within the bucket, while denying them any write or delete permissions. Other teams should have no access to this folder. Which IAM policy construct should the administrator use to achieve this granular control?
- AResource-based policy with 'Allow' on specific actions and 'Deny' on others.
- BIdentity-based policy with 'Allow' on the bucket and 'Deny' on the folder.
- CRole-based access control (RBAC) with a custom role for read-only access to the folder.
- DAttribute-based access control (ABAC) using tags for the folder and team.
Show answer & explanationAnswer & explanation
Correct answer: C. Role-based access control (RBAC) with a custom role for read-only access to the folder.
Role-based access control (RBAC) allows the creation of a custom role that explicitly defines read-only permissions for the specific folder. This role can then be assigned to the development team, ensuring they only have the required access and no others, while other teams are not assigned this role, thus having no access.
Why the other options are wrong
- A. While a resource-based policy can be used, RBAC (often implemented via identity-based policies and roles) is a more structured and manageable approach for assigning permissions to groups of users/teams for specific resources.
- B. An identity-based policy with 'Allow' on the bucket and 'Deny' on the folder would be overly complex and potentially problematic, as 'Deny' statements always override 'Allow'. A more precise approach is needed.
- D. ABAC uses attributes (tags) for more dynamic and fine-grained control, but for a fixed 'read-only' permission to a 'specific folder' for a 'specific team', RBAC is typically simpler and more appropriate if the criteria are static.
Role-Based Access Control (RBAC)
A method of access control where permissions are associated with roles, and users are assigned to roles, simplifying the management of complex access rights.
- Permissions assigned to roles
- Users assigned to roles
- Simplifies access management
Memory trick: Roles are like job titles, giving specific access to specific folders.