AWS Certified Security – Specialty — Question 201

A developer is building a serverless application hosted on AWS that uses Amazon Redshift as a data store. The application has separate module for read/write and read-only functionality. The modules need their own database users for compliance reasons.
Which combination of steps should a security engineer implement to grant appropriate access? (Choose two.)

Answer options

Correct answer: C, D

Explanation

The correct answers, C and D, allow for the specific configuration of database access through IAM policies and the creation of local database users, ensuring compliance. Options A and B focus on network-level access controls, which are not sufficient for managing individual user permissions. Option E incorrectly suggests using an IAM user instead of a database user, which does not meet the requirement for database-specific access.