SCS-C02 Management and Security Governance Practice Question
A security engineer is auditing IAM policies. The engineer wants to identify if any policy grants 'Effect: Allow' with 'Action: *' and 'Resource: *'. Which TWO AWS services can be used to detect such overly permissive policies?
⚠ Common exam trap
The trap is selecting CloudTrail or GuardDuty because they are 'security' services — candidates must distinguish between activity logging/threat detection and policy content analysis, which is the domain of Config and IAM Access Analyzer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config [CORRECT] is right because it continuously evaluates IAM policies against managed or custom rules (e.g., iam-policy-no-statements-with-admin-access) and can flag policies containing Effect: Allow with Action: * and Resource: *, which is exactly the overly permissive pattern being audited. IAM Access Analyzer [CORRECT] is also correct because its policy validation and findings (including checks for overly permissive policies such as those granting full administrative access) can identify policies with Action: * and Resource: * on Allow statements. AWS CloudTrail is not correct because it records API activity and events, not policy permission analysis. AWS Trusted Advisor is not correct because its security checks focus on broad best-practice items like open ports or MFA, not parsing IAM policy statements for wildcard Action/Resource. Amazon GuardDuty is not correct because it detects suspicious activity and threats from logs, not static IAM policy permissiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API activity and management events; it logs who called what, not the contents of IAM policy documents, so it cannot enumerate wildcard Allow statements. It is tempting because it is the audit service, and it would be correct for investigating who created or modified a policy after the fact.
- ✗
AWS Trusted Advisor
Why it's wrong here
Trusted Advisor checks cost, performance, fault tolerance, service quotas and security best practise, but its security category covers items such as open S3 buckets and exposed access keys, not wildcard IAM policy statements. It is tempting as a free advisory tool, and it would be correct for broad account hygiene recommendations.
- ✓
AWS Config
Why this is correct
AWS Config continuously records resource configurations and evaluates them against managed or custom rules, so a rule can flag IAM policies whose statements contain Action: * with Resource: *. This satisfies the requirement to detect overly permissive policies across accounts.
- ✓
IAM Access Analyzer
Why this is correct
IAM Access Analyzer analyses resource-based policies and, through policy validation and unused-access findings, identifies overly permissive statements such as Action: * paired with Resource: *. It directly satisfies the audit requirement to surface wildcard Allow grants.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty is a threat-detection service analysing CloudTrail, VPC Flow Logs and DNS logs for malicious behaviour; it does not parse IAM policy documents for wildcard Action and Resource combinations. It is tempting because it surfaces security findings, and it would be correct for detecting compromised credentials or crypto-mining activity.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.