SCS-C02 exam dumps

SCS-C02 practice question 316 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 316

Select 3

An application hosted on an EC2 instance is receiving 'Access Denied' errors when attempting to access an S3 bucket. As a security expert, you need to troubleshoot the issue. Which steps should you take to identify and resolve the root cause?

  1. A

    Check the CloudTrail logs to verify if the application made requests to the S3 bucket and analyze the logged error messages.

  2. B

    Review the IAM role attached to the EC2 instance to ensure it has the necessary permissions to access the S3 bucket.

  3. C

    Use the IAM Access Advisor to confirm whether the IAM role attached to the EC2 instance has been granted access to the S3 bucket in the past 90 days.

  4. D

    Use the IAM Policy Simulator to test the policies attached to the IAM role and verify whether they grant the required permissions for S3 access.

  5. E

    Manually add a new IAM policy to the EC2 instance that allows full access to all S3 buckets.

Show answer and explanation

Correct answers: A, B, D

Explanation

To troubleshoot authorization issues, it is essential to use the appropriate tools to identify and resolve the problem without introducing security risks. Checking CloudTrail logs helps you understand what went wrong and why. Reviewing the IAM role ensures the permissions are properly configured, and the IAM Policy Simulator allows you to test policies to confirm they grant the required access. Using IAM Access Advisor or adding overly permissive policies are not appropriate in this scenario as they do not directly address the root cause and could lead to security vulnerabilities.

  • A. Correct.

    This is correct. CloudTrail provides detailed logs of all API calls made to AWS services, including error messages, which can help identify why access is being denied.

  • B. Correct.

    This is correct. Reviewing the IAM role attached to the EC2 instance ensures that the role has the proper permissions required to access the S3 bucket.

  • C. Incorrect.

    This is incorrect. IAM Access Advisor only shows which services the role has accessed in the past 90 days and does not provide permission details for the specific S3 bucket.

  • D. Correct.

    This is correct. The IAM Policy Simulator can be used to simulate and verify whether the attached policies grant sufficient permissions for the desired action (e.g., S3 access).

  • E. Incorrect.

    This is incorrect. Manually adding a policy with full S3 access could introduce excessive permissions, violating the principle of least privilege and creating a security risk.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam