Skip to training content
CertGraph

Cross-account read-only access without static credentials

Medium
Secure Architectures

Task 1.1: Design secure access to AWS resources

Question
Watch the method

Predict first. Then watch short phrases—not full sentences—drive the decision.

Scenario

Pinebrook Freight runs a data account that owns the S3 bucket holding the curated shipment extract, and a separate analytics account whose EC2 reporting fleet rebuilds dashboards each night.

The fleet needs read-only access to the curated/shipments/ prefix; the eleven other prefixes in the same bucket hold raw carrier invoices the analytics team is not cleared to open.

The security lead adds two rules the design must respect: no long-lived access keys may exist in the analytics account, and no second copy of the extract may be stored outside the data account.

Question

Which design should the security lead approve for the reporting fleet?

Answer options

How certain is your prediction?

Model → Coach → Solo·Model · step 1 of 5 · not started
Activity timeline · 1 events
  1. 01coach · Make a prediction, record your confidence, then watch the reasoning method.