AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An operations engineer just created an Amazon S3 bucket in a new AWS account. Minutes later security tooling reports that a principal from another AWS account can read objects in the bucket, even though the engineer believes cross-account access is blocked. The engineer must quickly identify which policy grants this external access without adding logging or extra scanning services. Which solution meets these requirements?
Create an account-level IAM Access Analyzer in the Region and review its findings for the bucket to see the policy statement permitting external access.
Enable Amazon S3 server access logging on the bucket and manually inspect the log files to determine which policy was evaluated.
Use AWS CloudTrail Lake to run a query on recent GetObject events and trace the IAM policies attached to the calling principal.
Run an Amazon Macie bucket assessment and use the generated Policy Findings report to locate the offending statement.
IAM Access Analyzer continuously evaluates resource-based policies and produces a finding whenever a resource is shared outside the account. The finding shows the bucket ARN, the external principal, and the exact policy statement that allows the access, enabling rapid remediation with no additional instrumentation. S3 server access logs, CloudTrail Lake queries, and Amazon Macie assessments can reveal who accessed the bucket, but they do not automatically analyze policies or pinpoint the statement that granted the permission, and they require extra configuration or cost.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is IAM Access Analyzer and how does it work?
Open an interactive chat with Bash
Why is CloudTrail Lake not recommended for this scenario?
Open an interactive chat with Bash
How does IAM Access Analyzer compare to Amazon Macie in this scenario?
Open an interactive chat with Bash
What is IAM Access Analyzer?
Open an interactive chat with Bash
What is a resource-based policy in AWS?
Open an interactive chat with Bash
How does IAM Access Analyzer differ from S3 server access logging?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .