SCS-C02 exam dumps

SCS-C02 practice question 298 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 298

Select 2

An application running in your AWS environment is failing to access an S3 bucket. The application is using an IAM role for authentication. You need to troubleshoot this issue. Which combination of tools should you use to identify the root cause of the authentication failure?

  1. A

    AWS CloudTrail to review the application's API call history and identify any denied requests

  2. B

    IAM Access Advisor to determine if the IAM role has been used recently

  3. C

    IAM Policy Simulator to evaluate whether the IAM role's permissions allow access to the S3 bucket

  4. D

    AWS Trusted Advisor to check for security best practices related to S3 bucket permissions

  5. E

    Amazon S3 Access Logs to identify any access attempts to the S3 bucket

Show answer and explanation

Correct answers: A, C

Explanation

To troubleshoot authentication issues, you need tools that can help you analyze API call history and evaluate IAM policies. AWS CloudTrail provides detailed logs of API requests and their results, which can reveal if access was denied and why. IAM Policy Simulator allows you to test IAM policy configurations to determine if the permissions are correctly set up for the S3 bucket access. These tools together help identify and resolve authentication problems effectively.

  • A. Correct.

    AWS CloudTrail is useful for reviewing API call history and identifying denied requests, which can help pinpoint authentication issues.

  • B. Incorrect.

    IAM Access Advisor shows the recent usage of IAM roles or permissions, but it does not provide detailed information on API calls or access issues.

  • C. Correct.

    IAM Policy Simulator can evaluate whether the IAM role's permissions allow access to the S3 bucket, making it essential for troubleshooting authentication issues.

  • D. Incorrect.

    AWS Trusted Advisor provides recommendations for security and cost optimization but does not directly assist in diagnosing authentication issues.

  • E. Incorrect.

    Amazon S3 Access Logs can show access attempts, but they do not provide detailed information on IAM policy evaluation or authentication failures.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam