Courseiva

SCS-C02 Management and Security Governance Practice Question

A company's security team discovers that an IAM role has been assumed from an unexpected external AWS account. Which AWS service can be used to analyze the trust policy and identify unintended access?

⚠ Common exam trap

SCS-C02 often tests the specific purpose of IAM Access Analyzer versus CloudTrail Insights or Config — candidates pick CloudTrail Insights because it sounds like it analyzes activity, but Access Analyzer is the service for policy analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS IAM Access Analyzer

AWS IAM Access Analyzer analyzes resource-based policies, including IAM role trust policies, to identify resources shared with external entities. It can detect when a role's trust policy allows an unexpected external AWS account to assume it, providing findings that highlight unintended access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS IAM Access Analyzer

    Why this is correct

    AWS IAM Access Analyzer is correct because it performs automated, semantic analysis of the trust policy attached to the IAM role and identifies whether the role can be assumed by principals outside your AWS account or AWS organization. It generates concrete findings for external access, including the exact external principal and the action that grants access, so your security team can directly review and remediate the role. Other services merely log or aggregate activity; Access Analyzer specifically applies reachability logic to the policy statements.

  • ✗

    AWS CloudTrail Insights

    Why it's wrong here

    AWS CloudTrail Insights is incorrect because it analyzes management-event telemetry to detect unusual API activity, such as large increases in AssumeRole calls or abnormal access patterns, but it never inspects the role's trust policy to determine whether external access is permitted. It can show that an external principal did assume the role after the fact, but it cannot proactively reveal that the trust relationship grants that capability. Without previously recorded calls, it has no way to model the permissions that the policy allows.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is incorrect because it evaluates IAM role configurations against compliance rules and tracks configuration changes, but its standard rule set does not parse trust-policy statements for external principals or compute effective cross-account access. A role with a trust policy that allows any AWS account can still be marked compliant unless you write and maintain a custom Config rule specifically for that check. Config is a configuration recorder, not a policy reachability analyzer.

  • ✗

    AWS Security Hub

    Why it's wrong here

    AWS Security Hub is incorrect because it is an aggregation and correlation service that ingests findings from multiple enabled services, such as GuardDuty, Config, and IAM Access Analyzer, but it does not independently analyze IAM trust policies. If Access Analyzer is not enabled, Security Hub will never produce an external-access finding for this role, and even if a finding appears, the origin is Access Analyzer rather than Security Hub's own logic. Enabling Security Hub alone gives no visibility into the role's trust policy.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.