Courseiva
Identity and Access ManagementeasyMultiple ChoiceObjective-mapped

SCS-C03 Identity and Access Management Practice Question

A security team wants to identify which IAM roles in their AWS account have been granted permissions that allow access from external AWS accounts or public entities. Which AWS service should they use to automate this audit?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IAM Access Analyzer

AWS IAM Access Analyzer is designed specifically to identify resources that are shared with an external entity. It uses mathematical logic to analyze resource-based policies across S3, IAM roles, KMS keys, and more, providing a comprehensive list of findings that highlight potential unintended public or cross-account access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Secrets Manager

    Why it's wrong here

    AWS Secrets Manager is used for storing and rotating sensitive information like database credentials and API keys. It does not provide auditing capabilities for IAM policies or resource sharing. Its primary function is to enhance application security by removing hardcoded credentials from codebases and managing their lifecycle.

  • IAM Access Analyzer

    Why this is correct

    IAM Access Analyzer helps you identify the resources in your account, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a critical part of the security auditing process.

  • AWS Shield

    Why it's wrong here

    AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS. It focuses on network-level availability and infrastructure protection rather than identity management or the analysis of IAM permission sets and resource-based access control policies.

  • Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management service that continually scans AWS workloads for software vulnerabilities and unintended network exposure. While it focuses on security, it does not analyze IAM trust relationships or resource-based policies to identify external access patterns like IAM Access Analyzer does.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C03 question is part of Courseiva's 99-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.