AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An application that runs on Amazon EC2 assumes an IAM role named AppRole to write items to a DynamoDB table. After a recent change to IAM policies, the application receives AccessDenied errors when it calls PutItem. You are asked to identify exactly which statement in all attached identity-based and resource-based policies is blocking the request so that you can propose a fix. Which AWS tool will give you the most direct, line-by-line evaluation of every policy that applies to AppRole for this specific API call?

  • IAM Access Analyzer

  • IAM policy simulator

  • AWS CloudTrail Event history

  • AWS Trusted Advisor security checks

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot