Question 1 · choose 1
A developer receives an AccessDenied error when calling s3:PutObject on a bucket. The developer's IAM user has several identity-based policies and a permissions boundary. The operations team wants to find out which policy denies the call and to test a corrected policy before attaching it, without changing anything in the account. Which tool should the team use?
- AIAM Access Analyzer external access findings for the account
- BThe IAM policy simulator in the IAM console
- CAWS Trusted Advisor security checks
- DThe IAM credential report for the account
Show the answer and why
AIAM Access Analyzer external access findings for the account
Incorrect
External access analyzers identify resources that are shared with an external entity. They do not evaluate one user's request.
BThe IAM policy simulator in the IAM console
Correct
The simulator evaluates a user's identity policies, permissions boundary and SCPs for an action without sending a real request, shows which policy produced the result, and can test new policies that are not attached.
CAWS Trusted Advisor security checks
Incorrect
Trusted Advisor inspects the environment against best practices and makes recommendations. It does not explain a specific denied request.
DThe IAM credential report for the account
Incorrect
The credential report lists users and the status of their passwords, access keys and MFA devices, not policy decisions.
"Why is this call denied, and would this policy fix it?" is the policy simulator's question; it tests without touching the account.
AWS documentation