SCS-C02 exam dumps

SCS-C02 practice question 319 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 319

Select 3

A developer is unable to access an Amazon S3 bucket despite having a policy attached to their IAM role that explicitly grants access. How can you troubleshoot this issue to identify the root cause of the authorization failure?

  1. A

    Use AWS CloudTrail to review recent API activity for access denied errors.

  2. B

    Analyze the IAM Access Advisor to verify whether the S3 bucket permissions are being utilized.

  3. C

    Use the IAM policy simulator to test the evaluation of the developer's permissions for the specific S3 bucket.

  4. D

    Check the S3 bucket policy to confirm that it does not explicitly deny access to the developer's role.

  5. E

    Inspect the resource-based policies of other AWS services that may interact with the S3 bucket.

Show answer and explanation

Correct answers: A, C, D

Explanation

To troubleshoot authorization issues, it's essential to investigate API activity using AWS CloudTrail to determine if access was denied and why. The IAM policy simulator allows you to test permissions for the specific IAM role and resource, helping to pinpoint misconfigured policies. Additionally, explicit deny statements in an S3 bucket policy can override IAM allow permissions, so reviewing the bucket policy is critical. IAM Access Advisor and unrelated resource-based policies are not directly useful for this scenario.

  • A. Correct.

    Correct. AWS CloudTrail provides detailed logs of API activity, which can help identify if access was denied and why.

  • B. Incorrect.

    Incorrect. IAM Access Advisor shows which services are being accessed or not used by an IAM entity, but it does not provide detailed insights into specific permission evaluations for an S3 bucket.

  • C. Correct.

    Correct. The IAM policy simulator is a critical tool to evaluate permissions for a specific IAM entity and resource, and can help identify if any policies are incorrectly configured.

  • D. Correct.

    Correct. S3 bucket policies can override IAM permissions, and an explicit deny in the bucket policy would block access regardless of IAM grants.

  • E. Incorrect.

    Incorrect. While resource-based policies for other AWS services can affect access, they are not relevant unless the S3 bucket is integrated with those services. This is outside the scope of directly troubleshooting the developer's access issue.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam