SCS-C02 exam dumps

SCS-C02 practice question 303 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 303

Single answer

Your organization uses an S3 bucket to store sensitive financial reports. To enhance security, you are tasked with ensuring that only users in the 'FinanceTeam' IAM group can access this bucket, and all access must be logged. After creating a bucket policy, you find that some users outside of the 'FinanceTeam' group are still able to access the bucket. What is the most likely reason for this issue?

  1. A

    There is an IAM policy attached to users outside the 'FinanceTeam' group that grants access to the bucket.

  2. B

    The bucket policy is missing a condition to restrict access to the 'FinanceTeam' group.

  3. C

    The S3 bucket does not have logging enabled, which is preventing restriction enforcement.

  4. D

    The bucket is publicly accessible due to an S3 Block Public Access setting being disabled.

Show answer and explanation

Correct answer: A

Explanation

IAM policies and bucket policies are complementary, and permissions are evaluated based on the combination of both. If users have IAM policies attached to them that grant access to the S3 bucket, those permissions will apply even if the bucket policy restricts access to the 'FinanceTeam' group. To fix the issue, analyze and adjust IAM policies to ensure only the intended users have access.

  • A. Correct.

    Correct. If an IAM policy is attached to users outside the 'FinanceTeam' group that grants access to the bucket, it will override or complement the bucket policy, potentially allowing unintended access.

  • B. Incorrect.

    Incorrect. A bucket policy condition can help refine access but is not required to restrict access to a specific IAM group. The issue is more likely related to IAM policies granting access elsewhere.

  • C. Incorrect.

    Incorrect. Logging does not enforce access control; it is used for auditing and monitoring. The absence of logging would not cause unauthorized access.

  • D. Incorrect.

    Incorrect. While a disabled Block Public Access setting could make a bucket publicly accessible, the scenario specifies that access is limited to some users outside the designated group, not the entire public.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam