A company uses AWS Organizations to manage hundreds of accounts. Some accounts grant access to external AWS principals through cross-account IAM roles and Amazon S3 bucket policies. The company needs to determine which external principals have access to which accounts. Which solution will provide this visibility?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable AWS Identity and Access Management Access Analyzer at the organization level. Configure the organization as a zone of trust and filter findings by AWS account ID..
Why this is the answer
AWS IAM Access Analyzer is designed to identify resources shared with external entities. By enabling it at the organization level and configuring the organization as a zone of trust, it can analyze all accounts within the organization for cross-account access. It specifically identifies access granted through IAM roles and S3 bucket policies to external principals, directly addressing the problem statement. Filtering by AWS account ID allows the company to pinpoint which accounts have external access. Creating a custom AWS Config rule would require significant development and maintenance for each type of resource and access pattern, making it less efficient than Access Analyzer. Amazon Inspector focuses on vulnerability management and security best practices, not specifically on identifying external access granted through IAM policies. Amazon GuardDuty is a threat detection service that identifies anomalous behavior and potential threats, not a tool for auditing explicit access policies.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed