A company's security team discovers that an IAM role has been assumed from an unexpected external AWS account. Which AWS service can be used to analyze the trust policy and identify unintended access?
AWS IAM Access Analyzer is correct because it performs automated, semantic analysis of the trust policy attached to the IAM role and identifies whether the role can be assumed by principals outside your AWS account or AWS organization. It generates concrete findings for external access, including the exact external principal and the action that grants access, so your security team can directly review and remediate the role. Other services merely log or aggregate activity; Access Analyzer specifically applies reachability logic to the policy statements.
Why this answer
AWS IAM Access Analyzer analyzes resource-based policies, including IAM role trust policies, to identify resources shared with external entities. It can detect when a role's trust policy allows an unexpected external AWS account to assume it, providing findings that highlight unintended access.
Exam trap
SCS-C02 often tests the specific purpose of IAM Access Analyzer versus CloudTrail Insights or Config — candidates pick CloudTrail Insights because it sounds like it analyzes activity, but Access Analyzer is the service for policy analysis.
How to eliminate wrong answers
Option B is wrong because CloudTrail Insights detects unusual API activity patterns but does not analyze trust policies for external access. Option C is wrong because AWS Config evaluates resource configurations against rules but does not specifically analyze trust policies for external principals. Option D is wrong because Security Hub aggregates findings from various services but does not itself analyze trust policies; it relies on services like Access Analyzer.