Which additional actions should the solutions architect take to meet these requirements?

1 Comment

  1. Brenda
    Author

    I value that the answer is:
    Create an IAM role in the Organizations master account with permissions to use the Cost Explorer API, and establish trust between the role and the analytics account. Update the Lambda function role and add sts:AssumeRole permissions. Assume the role in the master account from the Lambda function code by using the AWS Security Token Service (AWS STS) AssumeRole API call. Create a gateway endpoint for Amazon S3 in the analytics VPC. Create an S3 bucket policy that allows access only from the S3 endpoint.

Leave a Reply

Your email address will not be published. Required fields are marked *

13 − eight =