SOA-C02 exam dumps

SOA-C02 practice question 177 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 177

Select 4

An AWS administrator is troubleshooting an issue where a user is unable to access an S3 bucket despite being assigned an IAM policy that explicitly grants the necessary permissions. The administrator wants to identify the root cause of the access issue. Which combination of actions should the administrator take to troubleshoot this problem?

  1. A

    Use the IAM Policy Simulator to evaluate the user's permissions for the S3 bucket.

  2. B

    Check the S3 bucket policy to see if it has a Deny statement that overrides the IAM policy.

  3. C

    Review the AWS CloudTrail logs to determine if there are any recent API calls indicating access was denied.

  4. D

    Use AWS Trusted Advisor to review security best practices for the S3 bucket.

  5. E

    Run IAM Access Analyzer to identify any resource-based policies that affect access to the S3 bucket.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

When troubleshooting access issues, it is important to evaluate both identity-based (IAM policies) and resource-based (e.g., S3 bucket policies) permissions. The IAM Policy Simulator can simulate a user's permissions and pinpoint potential conflicts, while the S3 bucket policy should be reviewed for any explicit Deny statements. AWS CloudTrail logs offer detailed access and error logs that can clarify what happened when the user attempted access. Lastly, IAM Access Analyzer helps identify resource-based policies or trust relationships that may impact access. Trusted Advisor, while helpful for overall security guidance, is not specific to this scenario.

  • A. Correct.

    The IAM Policy Simulator is a useful tool to evaluate and simulate the user's permissions for the S3 bucket. It can help identify permission gaps or conflicts.

  • B. Correct.

    S3 bucket policies are resource-based policies that can override IAM policies. A Deny statement in the bucket policy could block access even if the IAM policy allows it.

  • C. Correct.

    AWS CloudTrail logs provide detailed information about API activity, including access denied errors. Reviewing these logs can help confirm the issue and its cause.

  • D. Incorrect.

    AWS Trusted Advisor is primarily a tool for reviewing best practices and identifying cost optimization or security improvements, but it is not specifically designed for troubleshooting access issues.

  • E. Correct.

    IAM Access Analyzer can be used to review resource-based policies and identify any external or internal access that could impact the user's ability to access the bucket.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam