AWS Certified Solutions Architect Professional SAP-C02 Practice Question

An enterprise operates more than 100 AWS accounts that are part of a single AWS Organizations hierarchy. The security team needs a scalable mechanism to audit least-privilege adherence. The solution must continuously detect IAM users and roles whose permissions are unused or overly permissive, surface policy-level recommendations to right-size those permissions, and centralize all findings in a designated security tooling account. The team wants to rely only on native AWS services and keep ongoing administration to a minimum. Which approach will BEST meet these requirements?

  • Enable Amazon Inspector across all accounts and schedule Inspector to continuously scan IAM policies for unused or overly permissive actions, routing findings to the security tooling account.

  • Create an AWS Config organization aggregator in the security tooling account and deploy the managed rule iam-policy-no-statements-with-admin-access to every account; use conformance packs to view compliance results.

  • Make the security tooling account the delegated administrator for AWS IAM Access Analyzer, create an organization-scoped unused access analyzer, and ensure an organization-level AWS CloudTrail trail is enabled so Access Analyzer can generate least-privilege policy recommendations.

  • Aggregate CloudTrail logs from each member account into an Amazon S3 bucket in the security tooling account, then use Amazon Athena queries invoked by scheduled AWS Lambda functions to locate principals that have not invoked any actions in 90 days and send alerts.

AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot