SOA-C02 exam dumps

SOA-C02 practice question 179 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 179

Select 2

An application team reports that a Lambda function is failing to access an S3 bucket. As a SysOps Administrator, you need to troubleshoot the issue. Which combination of actions should you take to identify the root cause? (Choose TWO)

  1. A

    Use the IAM policy simulator to test the Lambda function's IAM role policies for access to the S3 bucket.

  2. B

    Check the S3 bucket's server access logs to identify whether the Lambda function has been denied access.

  3. C

    Review the AWS CloudTrail logs for events related to the Lambda function's access attempts to the S3 bucket.

  4. D

    Enable AWS Config to monitor compliance of the S3 bucket's policies.

  5. E

    Use the AWS Trusted Advisor to verify permissions for the Lambda function and S3 bucket.

Show answer and explanation

Correct answers: A, C

Explanation

To troubleshoot access issues, you need to analyze both the IAM policies and the actual API calls being made. The IAM policy simulator helps determine whether permissions are correctly configured, while AWS CloudTrail logs provide a record of access attempts and potential errors. These tools are the most relevant for identifying the root cause of the Lambda function's access issues with the S3 bucket.

  • A. Correct.

    The IAM policy simulator is a useful tool to test whether an IAM policy attached to a role grants or denies access to specific resources, such as an S3 bucket. This can help identify if the Lambda function's role lacks the required permissions.

  • B. Incorrect.

    S3 server access logs provide detailed information about bucket access requests, but they are not the most direct or efficient tool for troubleshooting IAM permission issues.

  • C. Correct.

    AWS CloudTrail logs provide a detailed history of API calls made by AWS services, including the Lambda function's access attempts to the S3 bucket. This is essential for identifying the root cause of access issues.

  • D. Incorrect.

    AWS Config monitors resource compliance but is not designed for troubleshooting specific access issues like those between a Lambda function and an S3 bucket.

  • E. Incorrect.

    AWS Trusted Advisor provides general recommendations for security and cost optimization but does not offer detailed, actionable insights into IAM-related access issues.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam