A company uses AWS Organizations and deploys all resources (including IAM and S3 policies) via CloudFormation from CodeCommit. Developers in some accounts recently cannot access an S3 bucket. The bucket has a policy attached (not shown here). What should the DevOps engineer do to resolve the access problem?
Choose an answer
Tap an option to check your answer.
Correct answer: Ensure no SCP is blocking developer access to the S3 bucket and ensure no IAM permissions boundaries deny access to developer IAM users. Make necessary changes to the SCPs and IAM permissions boundaries in the CodeCommit repository and redeploy the changes through CloudFormation..
Why this is the answer
The most comprehensive solution is to check both Service Control Policies (SCPs) and IAM permissions boundaries. SCPs, applied at the AWS Organizations level, can explicitly deny actions across entire accounts or OUs, overriding IAM policies. IAM permissions boundaries, attached to IAM principals, set
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed