SCS-C02 exam dumps

SCS-C02 practice question 297 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 297

Select 3

An application running on an EC2 instance is failing to access an S3 bucket. The instance has an IAM role attached, and you have verified that the S3 bucket policy allows access from the role. How can you troubleshoot this issue to identify the root cause?

  1. A

    Use AWS CloudTrail to check if there are any denied API calls from the IAM role to the S3 bucket.

  2. B

    Examine the IAM Access Advisor to verify whether the IAM role has recently accessed S3.

  3. C

    Use the IAM Policy Simulator to test the permissions granted to the IAM role for the S3 bucket.

  4. D

    Inspect the EC2 instance metadata to verify that the IAM role is correctly attached and accessible.

  5. E

    Check the bucket's ACL settings to ensure they do not override the bucket policy.

Show answer and explanation

Correct answers: A, C, D

Explanation

To troubleshoot authentication issues for accessing S3, you can use AWS CloudTrail to check for denied API calls, the IAM Policy Simulator to validate permissions, and EC2 instance metadata to ensure the IAM role is correctly attached. These tools help identify missing permissions, configuration issues, or attachment problems affecting access. IAM Access Advisor is not suitable for detailed troubleshooting in this scenario, and S3 ACLs are rarely used for access management when bucket policies are in place.

  • A. Correct.

    Correct. AWS CloudTrail logs will help you identify if there are any denied API calls and the reasons for the denial, such as missing permissions or incorrect configurations.

  • B. Incorrect.

    Incorrect. While IAM Access Advisor provides information about recently accessed services, it does not help in identifying or troubleshooting specific permission issues.

  • C. Correct.

    Correct. The IAM Policy Simulator allows you to simulate the permissions granted to the IAM role for S3 access, helping to determine if the role has the necessary permissions.

  • D. Correct.

    Correct. Checking the EC2 instance metadata ensures that the IAM role is correctly attached and accessible, which is critical for the application to use the assigned permissions.

  • E. Incorrect.

    Incorrect. S3 bucket ACLs are mostly deprecated in favor of bucket policies, and they do not override a bucket policy. This is not the primary troubleshooting step in this scenario.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam