CLF-C02 Security and Compliance Practice Question
A company wants to identify all resources in their AWS account that are accessible from outside the account — such as S3 buckets with public access or IAM roles with external trust. Which AWS service provides this analysis?
⚠ Common exam trap
Watch out — candidates often confuse Amazon Inspector's network reachability analysis with policy-based external access analysis, but Inspector only checks for network-level exposure (e.g., open ports), not for resource policies that grant permissions to external principals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Access Analyzer
AWS IAM Access Analyzer is the correct service because it analyzes resource-based policies (such as S3 bucket policies, IAM role trust policies, and KMS key policies) to identify resources shared with an external entity outside the AWS account. It uses a policy analysis engine that evaluates the principal, action, and condition elements to determine if a policy grants access to an external AWS account, an IAM user in another account, or a public principal (e.g., `"Principal": "*"`). This directly matches the requirement to find resources accessible from outside the account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that continuously scans Amazon EC2 instances, container images in Amazon ECR, and AWS Lambda functions for software vulnerabilities and unintended network exposure. Its findings focus on CVEs and network reachability from the internet, not on analyzing IAM resource policies to determine whether an external principal can access a resource. Inspector does not model policy logic or generate findings for cross-account access paths.
- ✓
AWS IAM Access Analyzer
Why this is correct
AWS IAM Access Analyzer uses automated reasoning to analyze the resource policies attached to supported resources such as S3 buckets, IAM roles, KMS keys, Lambda functions, SQS queues, and Secrets Manager secrets. It generates findings whenever a policy grants access to a principal from outside the account or outside your AWS Organization, identifying the external entity, actions, and conditions. This is exactly the static, policy-level analysis needed to detect resources reachable by external accounts.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service powered by machine learning and continuously monitors CloudTrail management events, VPC Flow Logs, and DNS logs for indicators of compromise. Its findings describe active or suspicious behavior, such as crypto mining, credential exfiltration, or unusual API calls, not the latent permissions granted by resource policies. GuardDuty cannot infer that a resource policy allows external access because it evaluates runtime activity, not the applicable policy logic.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration assessment and compliance service that records configuration changes and evaluates resources against managed or custom rules, such as requiring S3 buckets to be private or enabling encryption. While Config can flag a bucket as noncompliant if its policy is public, it applies predefined rule evaluation rather than automated reasoning to discover all external access paths across different resource types. Config does not produce findings that list the external principal, action, and condition that make a resource accessible from outside the organization.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.