問題文
A script on a compute instance has to call the object storage API and the security team refuses to place any long lived key on the instance. What arrangement satisfies both sides?
選択肢
- Put a signing key into the instance metadata and grant the metadata service the access that the script needs in a policy for the compartment.
- Put the instance into a dynamic group whose matching rule selects it and then grant that group the access that it needs in a policy.
- Put the instance into a regular user group and grant that group the access it needs in a policy so the script inherits the rights of the members.
- Put the instance into a security zone and grant the zone the access that the script needs in a policy for the compartment.