問題文
An engineer must be able to review the settings of the prevention policies but must not be able to change them, because policy changes go through a change board. Which approach fits the platform's access model?
選択肢
- Give the engineer an API key that has read-only scopes and no console access at all.
- Put the engineer's own host into a separate host group so that policy edits do not apply to it, which limits how far a mistaken change spreads.
- Assign a role that grants read access to policy configuration and withhold the role that grants the ability to modify it.
- Assign the role that grants full policy management, and rely on the change board to review the audit log afterwards so that unauthorized edits can be reverted.