SAP-C02 exam dumps

SAP-C02 practice question 223 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 223

Select 3

A company has multiple AWS accounts managed under a single AWS Organization. The organization uses AWS SSO (Single Sign-On) for user authentication. The security team has identified a scenario where some IAM roles in different accounts grant overly permissive permissions, resulting in potential security risks. As a solutions architect, what steps can you take to ensure that users assume only the required roles with minimal permissions across all accounts?

  1. A

    Use SCPs (Service Control Policies) at the organizational unit level to limit the permissions granted to IAM roles.

  2. B

    Enable AWS Organizations' consolidated billing to track role usage and enforce restrictions.

  3. C

    Review and update the IAM role trust policies to allow assumption only from specific AWS SSO-managed identities.

  4. D

    Use AWS IAM Access Analyzer to identify and flag roles with excessive permissions.

  5. E

    Disable role assumption entirely for all accounts under the AWS Organization.

Show answer and explanation

Correct answers: A, C, D

Explanation

To mitigate security risks from overly permissive IAM roles, you can take several measures. SCPs enforce permission boundaries at the organizational level, ensuring accounts cannot exceed specified permissions. Updating IAM role trust policies limits who can assume roles, reducing the attack surface. IAM Access Analyzer is a powerful tool to identify and address roles or policies that grant excessive permissions. These combined steps reinforce the principle of least privilege while maintaining operational efficiency.

  • A. Correct.

    Service Control Policies (SCPs) are used at the organizational level to define permission boundaries for all accounts in an organization or organizational units. This can help restrict IAM roles from being overly permissive.

  • B. Incorrect.

    While consolidated billing is useful for cost tracking, it doesn't directly address or restrict over-permissive roles.

  • C. Correct.

    IAM role trust policies define who or what can assume a role. By limiting trust policies to only specific AWS SSO-managed identities, you can prevent unauthorized assumptions of roles.

  • D. Correct.

    AWS IAM Access Analyzer scans for roles or policies granting excessive permissions and helps identify potential security risks. This is critical in ensuring least privilege access.

  • E. Incorrect.

    Disabling all role assumption is not a practical solution. It denies access to legitimate use cases and is not aligned with best practices.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam