Quanta ML wants to create a least-privilege policy for an application role based on actual API usage over the last month. They plan to use IAM Access Analyzer policy generation. Which steps should they take? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Verify CloudTrail has logged the role’s activity in the relevant regions and time range so Access Analyzer has events to analyze., Use IAM Access Analyzer to Generate policy for the role over the desired time window and attach the resulting customer managed policy to the role..
Why this is the answer
To generate a least-privilege policy using IAM Access Analyzer, it requires CloudTrail logs to analyze the actual API calls made by the role. Therefore, verifying that CloudTrail has logged the role's activity in the relevant regions and time range is a crucial first step. Once sufficient CloudTrail data is available, you can use IAM Access Analyzer's policy generation feature, specifying the desired time window. The generated policy will reflect the observed API actions, and this customer-managed policy can then be attached to the role to enforce least privilege. Enabling an organization-level analyzer and suppressing external access findings is for identifying unintended external access, not for generating least-privilege policies based on internal API usage. AWS Config records resource configuration changes, not individual API calls for policy generation. IAM Access Advisor provides information on when services were last accessed, which is different from the detailed API call data needed for policy generation and cannot be directly pasted into an inline policy for this purpose.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed