SCS-C02 Management and Security Governance Practice Question
A security engineer notices that an S3 bucket policy allows access to a principal from another AWS account. Which AWS feature can be used to check if this external access is intended?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Access Analyzer
IAM Access Analyzer generates findings for external access to S3 buckets. You can review and archive findings if intended.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Trusted Advisor bucket permissions check
Why it's wrong here
AWS Trusted Advisor's S3 bucket permissions check only scans for buckets that are exposed to 'Everyone' or 'Any Authenticated AWS User' via bucket ACLs or bucket policies, which is equivalent to checking for public access. It does not flag policies that grant access to a specific external AWS account, nor does it provide any mechanism to annotate a finding as 'intended' after manual review. In this scenario the policy likely grants cross-account access to a particular external principal, so Trusted Advisor would not even identify it as a risk, let alone help validate intent.
- ✗
AWS Config rule s3-bucket-public-read-prohibited
Why it's wrong here
The AWS Config managed rule s3-bucket-public-read-prohibited only checks whether a bucket allows anonymous public read access, typically against the canned ACL 'public-read' or a bucket policy using a wildcard principal with read actions. It is a compliance rule that returns a binary compliant/non-compliant result and has no workflow for you to mark access as intentional. Because cross-account read access to a named external account is not 'public read', the rule would remain compliant and provide no signal that the external principal might be unintended.
- ✗
AWS CloudTrail event history
Why it's wrong here
CloudTrail event history captures the API calls that affect a bucket — for example, who called PutBucketPolicy, when, and with what policy document — so it can show the exact moment the questionable permission was created. However, it is a reactive audit log; it cannot classify the resulting access as intended or accidental, and it does not proactively enumerate which external principals currently have access. You would still need to manually compare the logged policy against business requirements, which is precisely the review that IAM Access Analyzer automates.
- ✓
AWS IAM Access Analyzer
Why this is correct
IAM Access Analyzer continuously analyzes resource-based policies and creates findings whenever access to a resource like an S3 bucket is granted to an external principal — an AWS account outside your zone of trust or an anonymous principal. Each finding details the external account/principal, the exact actions allowed, and the policy statement causing the access, so you can determine whether that access is intended. In the console you can then mark the finding as 'Archive' for intended access or take remediation action for unintended access, which is the only option here that directly answers the security engineer's question.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.