SCS-C02 exam dumps

SCS-C02 practice question 299 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 299

Select 3

A developer is trying to access an S3 bucket but is receiving an 'Access Denied' error. As a security engineer, you need to troubleshoot the issue. Which steps should you take to identify the cause of the problem?

  1. A

    Use CloudTrail to check if there are any recent API calls made by the developer to the S3 bucket.

  2. B

    Use the IAM Access Advisor to verify if the developer's IAM role has the necessary S3 permissions.

  3. C

    Use the IAM Policy Simulator to simulate the developer's permissions and validate access to the S3 bucket.

  4. D

    Review the S3 bucket policy to ensure it grants access to the developer's IAM role or user.

  5. E

    Check the S3 bucket encryption settings to determine if they are blocking access.

Show answer and explanation

Correct answers: A, C, D

Explanation

To troubleshoot 'Access Denied' errors, you should use tools like CloudTrail to check if access attempts were logged and denied, the IAM Policy Simulator to evaluate IAM permissions, and review the S3 bucket policy to ensure it allows access. IAM Access Advisor is useful for assessing service usage but does not help in this specific scenario. S3 encryption settings do not impact access control.

  • A. Correct.

    CloudTrail provides logs of recent API calls, including any 'Access Denied' errors, which can help identify if the developer's access attempt reached AWS and was denied.

  • B. Incorrect.

    IAM Access Advisor shows service usage information for a role or user, but it does not validate specific permissions for accessing a resource like an S3 bucket.

  • C. Correct.

    The IAM Policy Simulator is a tool to evaluate and troubleshoot IAM policies and permissions. Simulating the developer's access to the S3 bucket helps identify if IAM policies are blocking access.

  • D. Correct.

    The S3 bucket policy could explicitly deny or fail to allow access to the developer's IAM role or user. Reviewing the policy ensures it is correctly configured.

  • E. Incorrect.

    S3 bucket encryption settings do not block access to the bucket itself. They determine how data is encrypted but are unrelated to access control.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam