ISC Practice Question: Systems Security Implementation Verification And Validation
During a cloud security audit, you need to verify that IAM users do not have overly permissive policies. Which AWS feature provides automated validation of IAM policy adherence to least privilege?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Access Analyzer
IAM Access Analyzer helps identify policies that provide public or cross-account access, a key part of validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Security Hub
Why it's wrong here
Security Hub aggregates alerts but does not perform the specific policy analysis offered by Access Analyzer.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail logs activity, it does not analyze policy permissions for over-privilege.
- ✗
AWS Trusted Advisor
Why it's wrong here
Trusted Advisor provides general recommendations, not deep policy analysis.
- ✓
AWS IAM Access Analyzer
Why this is correct
Access Analyzer validates that policies conform to security best practices and least privilege.
About these practice questions
One of 209 original ISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official (ISC)² exam blueprint
This ISC practice question is part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ISC exam.