SOA-C02 exam dumps

SOA-C02 practice question 178 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 178

Select 2

An application running in your AWS environment is failing to access an S3 bucket. The application uses an IAM role for authentication, and you need to troubleshoot the issue. Which combination of actions can help identify and resolve the root cause? (Choose TWO)

  1. A

    Use the IAM Policy Simulator to validate if the IAM role has sufficient permissions to access the S3 bucket.

  2. B

    Enable Amazon S3 Server Access Logging to verify whether the application has made any requests to the bucket.

  3. C

    Use AWS CloudTrail logs to track the API calls made by the application and identify any authorization failures.

  4. D

    Modify the S3 bucket policy to allow public access and confirm if the application can access the bucket.

  5. E

    Use the IAM Access Analyzer to identify any potential resource-based policy misconfigurations for the S3 bucket.

Show answer and explanation

Correct answers: A, C

Explanation

To troubleshoot IAM role-based access issues to an S3 bucket, the IAM Policy Simulator can validate whether the necessary permissions are in place, while AWS CloudTrail logs provide insights into API calls and authorization failures. These tools together help identify the root cause of the access issue without compromising security or relying on less effective methods.

  • A. Correct.

    The IAM Policy Simulator is a key tool to troubleshoot permissions issues. It allows you to test whether the IAM role has the necessary permissions for accessing the S3 bucket.

  • B. Incorrect.

    Amazon S3 Server Access Logging provides detailed information about access requests, but it is not suitable for troubleshooting IAM role-based access issues as it does not provide information about authorization failures.

  • C. Correct.

    AWS CloudTrail logs are essential for tracking API calls and identifying authorization failures, making it a critical tool for troubleshooting access issues.

  • D. Incorrect.

    Allowing public access to the S3 bucket is a security risk and does not resolve IAM role or policy-related access issues. This approach is not recommended.

  • E. Incorrect.

    IAM Access Analyzer is useful for identifying policy misconfigurations, but it is designed to analyze resource-based policies. For IAM role-based issues, it is less effective compared to the IAM Policy Simulator.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam