Soru

Zorluk: KolayAWS Service Catalog Portfolio and Product Management

A SysOps administrator needs to share an AWS Service Catalog portfolio with another AWS account. The administrator also wants to ensure that when users in the target account launch the products, the resources are created using a designated IAM role, regardless of the users' individual permissions. Which actions must the administrator take to configure this setup? (Select TWO.)

  1. Share the portfolio with the target AWS account or organization unit.Cevap
  2. Associate a launch constraint with the portfolio, specifying the designated IAM role.Cevap
  3. C
    Associate a template constraint with the portfolio, specifying the designated IAM role.
  4. D
    Grant the end users in the target account direct 'iam:AssumeRole' permissions to the designated IAM role.
  5. E
    Add the designated IAM role directly to the CloudFormation template's Resources section as a policy attachment.

Cevap

Share the portfolio with the target account or organization unit, and associate a launch constraint with the portfolio that specifies the designated IAM role.
To distribute products to another account and control launch permissions, the administrator must share the portfolio and apply a launch constraint specifying the target IAM role. The launch constraint ensures that AWS Service Catalog assumes the specified role to provision resources, bypassing the end users' permissions.

Adım Adım Çözüm

1
Distribute the portfolio to the target account.
The portfolio and its products become visible in the target account's AWS Service Catalog console.
Before users in another account can launch a product, the portfolio containing it must be explicitly shared.
2
Create and apply a launch constraint using an IAM role.
AWS Service Catalog will use this role's permissions to provision the resources during product launch.
A launch constraint allows users to deploy products even if they do not have direct permissions to create the underlying AWS resources.

Anahtar Kavram

Sharing AWS Service Catalog portfolios and applying launch constraints to manage provisioning permissions across accounts.
Bu soruyu puanla