Courseiva
DetectionhardMultiple SelectObjective-mapped

SCS-C03 Detection Practice Question

Which THREE of the following resource types are currently supported by IAM Access Analyzer to identify potential public or cross-account access?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Amazon S3 Buckets

IAM Access Analyzer helps identify resources in your organization and accounts that are shared with an external entity. It does this by analyzing resource-based policies. This helps security teams identify unintended access to sensitive data or infrastructure and is a critical part of the 'Detection' domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Amazon S3 Buckets

    Why this is correct

    IAM Access Analyzer analyzes S3 bucket policies to identify if a bucket is accessible by anyone on the internet or by other AWS accounts. This is one of the most common use cases for the service to prevent data leaks from misconfigured storage permissions.

  • AWS KMS Keys

    Why this is correct

    KMS key policies are analyzed to ensure that cryptographic keys are not inadvertently shared with external accounts. This is vital for maintaining the confidentiality and integrity of encrypted data, as unauthorized access to keys could lead to data decryption by external parties.

  • Amazon SQS Queues

    Why this is correct

    SQS queue policies are supported, allowing the analyzer to detect if a queue can be read from or written to by accounts outside the zone of trust. This prevents unauthorized message injection or consumption, which could disrupt application workflows or expose sensitive data.

  • Amazon DynamoDB Tables

    Why it's wrong here

    As of the current service definition, IAM Access Analyzer does not natively analyze DynamoDB tables directly via resource-based policies in the same way it does for S3 or SQS. Access to DynamoDB is typically controlled through IAM identity-based policies or VPC endpoints.

  • Amazon EC2 Security Groups

    Why it's wrong here

    Security Groups are stateful firewalls for EC2 instances and are not analyzed by IAM Access Analyzer. To detect public access via Security Groups, services like AWS Config or Amazon Inspector's Network Reachability package should be used instead, as they focus on network-level exposure.

About these practice questions

This SCS-C03 question is part of Courseiva's 99-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.