SAP-C02 exam dumps

SAP-C02 practice question 420 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 420

Select 2

Your company has a multi-account structure in AWS, where each account is managed using AWS Organizations. An audit reveals that several IAM roles in these accounts have permissions that go beyond their intended purpose, increasing the risk of security vulnerabilities. As a Solutions Architect, you are tasked with implementing the principle of least privilege access across all accounts. Which of the following actions should you take? (Select TWO.)

  1. A

    Use AWS IAM Access Analyzer to identify unused or overly permissive IAM roles and policies.

  2. B

    Attach the FullAccess policy to all IAM roles to standardize permissions across all accounts.

  3. C

    Enable Service Control Policies (SCPs) in AWS Organizations to restrict actions that are not necessary for business operations.

  4. D

    Manually review each IAM policy across all accounts and remove any policies that grant more than read-only access.

  5. E

    Implement permissions boundaries for IAM roles to set maximum permissions that cannot be exceeded.

Show answer and explanation

Correct answers: A, C

Explanation

The principle of least privilege access involves granting only the permissions necessary for a role or user to perform their tasks. In a multi-account setup, tools like AWS IAM Access Analyzer help identify and remediate overly permissive roles and policies. Service Control Policies (SCPs) enforce organization-wide guardrails, ensuring that actions within accounts remain restricted to what's necessary for operations. These approaches are scalable and effective compared to manual efforts or overly permissive policies.

  • A. Correct.

    Correct. AWS IAM Access Analyzer can help identify unused or overly permissive IAM roles and policies, which is a critical step in implementing the principle of least privilege.

  • B. Incorrect.

    Incorrect. Attaching the FullAccess policy to all IAM roles contradicts the principle of least privilege, as it grants permissions that may not be required for specific roles.

  • C. Correct.

    Correct. Enabling Service Control Policies (SCPs) in AWS Organizations allows you to enforce permissions at the organizational level, ensuring accounts cannot perform actions beyond what is necessary.

  • D. Incorrect.

    Incorrect. Manually reviewing each IAM policy is not scalable in a multi-account setup. Automated tools like IAM Access Analyzer or SCPs are more effective.

  • E. Incorrect.

    Incorrect. While permissions boundaries are useful in specific cases, they are not designed to evaluate existing overly permissive roles or policies across accounts.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam