AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An operations engineer is investigating why an EC2 instance that uses an IAM role cannot upload objects to an Amazon S3 bucket in the same account. The role's identity policy explicitly allows s3:PutObject on the bucket. CloudTrail logs for the failed API call show an AccessDenied error. The engineer wants to quickly determine whether the deny originates from the role's identity policy or the bucket's resource policy without manually examining JSON documents. Which AWS tool should the engineer use?

  • Use the IAM policy simulator to test the role against the bucket and action.

  • Review findings from IAM Access Analyzer for the S3 bucket.

  • Initiate an Amazon Inspector assessment of the EC2 instance.

  • Run the AWS Trusted Advisor security check for Amazon S3 permissions.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot