SOA-C02 exam dumps

SOA-C02 practice question 184 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 184

Single answer

An organization has implemented Service Control Policies (SCPs) in AWS Organizations to restrict access to certain services and actions across multiple accounts. A SysOps Administrator is troubleshooting an issue where an IAM user is unable to perform the 's3:DeleteObject' action on an Amazon S3 bucket, even though the user has an attached IAM policy explicitly allowing this action. What should the SysOps Administrator check to resolve this issue?

  1. A

    Ensure that the S3 bucket policy does not explicitly deny the 's3:DeleteObject' action.

  2. B

    Verify that the SCP attached to the account allows the 's3:DeleteObject' action.

  3. C

    Check if the IAM user's permissions boundary allows the 's3:DeleteObject' action.

  4. D

    Confirm that the S3 bucket encryption settings are not restricting the 's3:DeleteObject' action.

Show answer and explanation

Correct answer: B

Explanation

Service Control Policies (SCPs) define the maximum permissions for accounts in an AWS Organization. Even if an IAM policy explicitly allows an action, the action will be blocked if the SCP denies it. In this scenario, verifying that the SCP attached to the account allows the 's3:DeleteObject' action is the correct step to resolve the issue. Other factors, such as bucket policies or permissions boundaries, are secondary and do not override SCPs.

  • A. Incorrect.

    While a bucket policy could deny access, this situation specifically involves SCPs and IAM permissions, making this option unrelated to the root cause.

  • B. Correct.

    SCPs are a key factor in determining whether an action is allowed at the account level. If the SCP denies the 's3:DeleteObject' action, no IAM policy or permissions boundary can override it.

  • C. Incorrect.

    Permissions boundaries are used to define the maximum permissions for the IAM user or role, but they do not override SCPs. Therefore, this is not the root cause in this scenario.

  • D. Incorrect.

    S3 bucket encryption settings do not impact the ability to perform actions like 's3:DeleteObject', so this option is irrelevant in this context.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam