Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer notices that an S3 bucket policy allows access to a principal from another AWS account. Which AWS feature can be used to check if this external access is intended?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS IAM Access Analyzer

IAM Access Analyzer generates findings for external access to S3 buckets. You can review and archive findings if intended.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor bucket permissions check

    Why it's wrong here

    AWS Trusted Advisor's S3 bucket permissions check only scans for buckets that are exposed to 'Everyone' or 'Any Authenticated AWS User' via bucket ACLs or bucket policies, which is equivalent to checking for public access. It does not flag policies that grant access to a specific external AWS account, nor does it provide any mechanism to annotate a finding as 'intended' after manual review. In this scenario the policy likely grants cross-account access to a particular external principal, so Trusted Advisor would not even identify it as a risk, let alone help validate intent.

  • ✗

    AWS Config rule s3-bucket-public-read-prohibited

    Why it's wrong here

    The AWS Config managed rule s3-bucket-public-read-prohibited only checks whether a bucket allows anonymous public read access, typically against the canned ACL 'public-read' or a bucket policy using a wildcard principal with read actions. It is a compliance rule that returns a binary compliant/non-compliant result and has no workflow for you to mark access as intentional. Because cross-account read access to a named external account is not 'public read', the rule would remain compliant and provide no signal that the external principal might be unintended.

  • ✗

    AWS CloudTrail event history

    Why it's wrong here

    CloudTrail event history captures the API calls that affect a bucket — for example, who called PutBucketPolicy, when, and with what policy document — so it can show the exact moment the questionable permission was created. However, it is a reactive audit log; it cannot classify the resulting access as intended or accidental, and it does not proactively enumerate which external principals currently have access. You would still need to manually compare the logged policy against business requirements, which is precisely the review that IAM Access Analyzer automates.

  • ✓

    AWS IAM Access Analyzer

    Why this is correct

    IAM Access Analyzer continuously analyzes resource-based policies and creates findings whenever access to a resource like an S3 bucket is granted to an external principal — an AWS account outside your zone of trust or an anonymous principal. Each finding details the external account/principal, the exact actions allowed, and the policy statement causing the access, so you can determine whether that access is intended. In the console you can then mark the finding as 'Archive' for intended access or take remediation action for unintended access, which is the only option here that directly answers the security engineer's question.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.