AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An EC2 instance-profile role named AppServerRole in account A receives AccessDenied errors when the application calls sts:AssumeRole on the cross-account role arn:aws:iam::222222222222:role/AnalyticsRole. You have confirmed that the trust policy on AnalyticsRole already trusts AppServerRole. To check whether any identity-based or session policies on AppServerRole block the call, you plan to use the IAM policy simulator. Which simulator configuration will give the most accurate view of the caller's effective permission?
Select AppServerRole as the principal, choose the sts:AssumeRole action, but leave the resource field blank so only identity-based policies are evaluated.
Select AnalyticsRole as the principal, choose the sts:AssumeRole action, and leave the resource field blank.
Run the simulator with the account A root user as the principal to reveal any explicit denies from lower-level policies.
Select AppServerRole as the principal, choose the sts:AssumeRole action, and specify arn:aws:iam::222222222222:role/AnalyticsRole as the resource.
Choose AppServerRole as the principal, select the sts:AssumeRole action, and enter arn:aws:iam::222222222222:role/AnalyticsRole as the resource. This setup tests all identity-based, session, and permissions-boundary policies that apply to AppServerRole for the specific role being assumed. Providing the exact resource ARN is essential because the simulator matches policy statements that list that ARN; leaving the resource blank could show an implicit deny even when a more specific allow statement exists. The simulator cannot evaluate the target role's trust policy, but you have already validated that separately. Running the simulation as AnalyticsRole or the account root user would not test the caller's policies, so those configurations give incomplete or irrelevant results.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the IAM Policy Simulator used for?
Open an interactive chat with Bash
What is the difference between identity-based and session policies?
Open an interactive chat with Bash
Why is the resource ARN required in the IAM Policy Simulator?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .