Cross-account read-only access without static credentials
Task 1.1: Design secure access to AWS resources
QuestionWatch the method
Predict first. Then watch short phrases—not full sentences—drive the decision.
Scenario
Pinebrook Freight runs a data account that owns the S3 bucket holding the curated shipment extract, and a separate analytics account whose EC2 reporting fleet rebuilds dashboards each night.
The fleet needs read-only access to the curated/shipments/ prefix; the eleven other prefixes in the same bucket hold raw carrier invoices the analytics team is not cleared to open.
The security lead adds two rules the design must respect: no long-lived access keys may exist in the analytics account, and no second copy of the extract may be stored outside the data account.
Question
Which design should the security lead approve for the reporting fleet?
Activity timeline · 1 events
- 01coach · Make a prediction, record your confidence, then watch the reasoning method.