Which AWS feature can detect if an Amazon S3 bucket or an IAM role has been shared with an external principal?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS IAM Access Analyzer.
Why this is the answer
AWS IAM Access Analyzer is the correct choice because it helps identify resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. It uses logic-based reasoning to analyze access policies and identify potential unintended access. AWS Service Catalog allows organizations to create and manage catalogs of IT services approved for use on AWS. AWS Systems Manager helps you gain operational insights and take action on your AWS resources. AWS Organizations helps you centrally manage and govern your environment as you grow and scale your AWS resources. While these services are useful for managing AWS environments, they do not specifically detect external access to S3 buckets or IAM roles.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed