Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator manages IAM roles for Amazon EC2 instances. The administrator needs to identify permissions that have never been used in the last 90 days to right-size the policies. Which AWS feature should be used to achieve this?

⚠ Common exam trap

It's easy for candidates to confuse IAM Access Analyzer unused access analysis with AWS CloudTrail Insights, but CloudTrail Insights focuses on anomalous activity patterns rather than a straightforward unused permissions report for policy right-sizing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IAM Access Analyzer unused access analysis

IAM Access Analyzer unused access analysis is the correct AWS feature because it specifically analyzes IAM roles and policies to identify permissions that have not been used within a specified time frame (e.g., 90 days). It provides a report of unused actions, allowing the administrator to right-size policies by removing unnecessary permissions. This directly addresses the requirement to identify unused permissions for EC2 instance roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail Insights

    Why it's wrong here

    AWS CloudTrail Insights is an anomaly detection service that uses machine learning to identify unusual API activity, such as anomalous request patterns or error rates. It does not generate a report of which IAM permissions have not been used over time, nor does it track service last accessed data. Since the requirement is to identify stale permissions for least privilege, CloudTrail Insights is not the right tool.

  • ✓

    IAM Access Analyzer unused access analysis

    Why this is correct

    IAM Access Analyzer unused access analysis examines the service last accessed data for IAM roles and users to identify which actions, services, and resources have not been used within a specified timeframe (e.g., 90 or 180 days). This feature produces findings that directly highlight unused permissions, allowing SysOps administrators to update policies and enforce least privilege. It is the only option listed that provides the historical usage data needed to detect and remove unnecessary access.

  • ✗

    IAM policy simulator

    Why it's wrong here

    The IAM policy simulator is a testing tool that evaluates the effects of a specific policy or set of policies against a simulated request, such as a chosen action, resource, and principal. It answers 'what if' authorization questions but does not analyze actual historical API calls or track permission usage over time. Because the task is to identify unused permissions, the simulator cannot provide the required evidence of non-usage.

  • ✗

    AWS Config managed rules

    Why it's wrong here

    AWS Config managed rules continuously evaluate the configuration states of AWS resources for compliance, such as verifying that security groups do not allow unrestricted inbound traffic or that S3 buckets have versioning enabled. They do not monitor IAM principal behavior, nor do they analyze permission usage patterns across a role's actions. Consequently, Config cannot determine whether a role's permissions are being used or are stale.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.