Department documents share one index.
Hide unauthorized evidence.
Choose two controls.
Apply identity-based filters before retrieval and test allow/deny cases, audit logs, and citation authorization.
Detailed explanation
Unauthorized evidence is excluded.
Unauthorized evidence is excluded.
Boundaries are verified.
Boundaries are verified.
The model is not an authorization layer.
The model is not an authorization layer.
Least privilege is violated.
Least privilege is violated.
Try it yourself
An example you can run in a temporary verification environment.
AWS公式AIF-C01 Domain 3.1・5.2の検索認可、最小権限、監査を確認する。Expected result
モデルの指示だけに頼らず、検索・引用・監査の各段階で権限を適用できる。Key points
- Authorization filter
- Least privilege
- Audit
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.