AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An EC2 instance-profile role named AppServerRole in account A receives AccessDenied errors when the application calls sts:AssumeRole on the cross-account role arn:aws:iam::222222222222:role/AnalyticsRole. You have confirmed that the trust policy on AnalyticsRole already trusts AppServerRole. To check whether any identity-based or session policies on AppServerRole block the call, you plan to use the IAM policy simulator. Which simulator configuration will give the most accurate view of the caller's effective permission?

  • Run the simulator with the account A root user as the principal to reveal any explicit denies from lower-level policies.

  • Select AppServerRole as the principal, choose the sts:AssumeRole action, and specify arn:aws:iam::222222222222:role/AnalyticsRole as the resource.

  • Select AppServerRole as the principal, choose the sts:AssumeRole action, but leave the resource field blank so only identity-based policies are evaluated.

  • Select AnalyticsRole as the principal, choose the sts:AssumeRole action, and leave the resource field blank.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot