Skip to content
BytePatterns

SOA-C03 · Domain 4: Security and Compliance · 16% of the exam

Task 4.1: Implement and manage security and compliance tools and policies.

Controlling and auditing access: IAM policies, roles, MFA and conditions, finding why access fails with CloudTrail, IAM Access Analyzer and the policy simulator, guardrails for many accounts with Organizations and SCPs, Trusted Advisor checks, and AWS Config rules and conformance packs.

Study it

  • IAM in practice: policies, roles, MFA, conditions and federation

    Partly covered by: Shared Responsibility & IAM

  • Troubleshooting access: CloudTrail, IAM Access Analyzer and the policy simulator

    Partly covered by: Shared Responsibility & IAM

  • Many accounts: Organizations, SCPs, Control Tower and IAM Identity Center

    Partly covered by: Organizations, SCPs & Control Tower

  • Compliance checks: Trusted Advisor, AWS Config rules and conformance packs

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A developer receives an AccessDenied error when calling s3:PutObject on a bucket. The developer's IAM user has several identity-based policies and a permissions boundary. The operations team wants to find out which policy denies the call and to test a corrected policy before attaching it, without changing anything in the account. Which tool should the team use?

  1. AIAM Access Analyzer external access findings for the account
  2. BThe IAM policy simulator in the IAM console
  3. CAWS Trusted Advisor security checks
  4. DThe IAM credential report for the account
Show the answer and why
  • AIAM Access Analyzer external access findings for the account

    Incorrect

    External access analyzers identify resources that are shared with an external entity. They do not evaluate one user's request.

  • BThe IAM policy simulator in the IAM console

    Correct

    The simulator evaluates a user's identity policies, permissions boundary and SCPs for an action without sending a real request, shows which policy produced the result, and can test new policies that are not attached.

  • CAWS Trusted Advisor security checks

    Incorrect

    Trusted Advisor inspects the environment against best practices and makes recommendations. It does not explain a specific denied request.

  • DThe IAM credential report for the account

    Incorrect

    The credential report lists users and the status of their passwords, access keys and MFA devices, not policy decisions.

"Why is this call denied, and would this policy fix it?" is the policy simulator's question; it tests without touching the account.

Question 2 · choose 1

A company's compliance rules say that workloads may run only in eu-west-1 and eu-central-1. The company uses AWS Organizations with all features enabled. Users and roles in every member account, including account administrators and roles created in the future, must be unable to use other Regions, while global services such as IAM keep working. What should the operations team do?

  1. AAttach a permissions boundary that allows only the two Regions to every IAM user and role
  2. BDeploy an AWS Config rule that flags resources created in other Regions
  3. CAttach an SCP that denies other values of aws:RequestedRegion, exempting global services
  4. DCreate IAM Identity Center permission sets that allow only the two Regions
Show the answer and why
  • AAttach a permissions boundary that allows only the two Regions to every IAM user and role

    Incorrect

    A boundary is set on one IAM user or role at a time and limits only that entity. Roles created later would each need it too.

  • BDeploy an AWS Config rule that flags resources created in other Regions

    Incorrect

    Config rules evaluate resources against a desired configuration. They report a violation after the fact instead of preventing it.

  • CAttach an SCP that denies other values of aws:RequestedRegion, exempting global services

    Correct

    SCPs set the maximum permissions for IAM users and roles in member accounts, and aws:RequestedRegion compares the Region called. Global services such as IAM need an exemption because their endpoint is in us-east-1.

  • DCreate IAM Identity Center permission sets that allow only the two Regions

    Incorrect

    Permission sets define the access that Identity Center assigns to its users and groups. They do not limit IAM users and roles that exist in the member accounts.

A preventive guardrail for every principal in member accounts is an SCP. The Region condition must exempt global services, or calls to IAM would be denied too.

Question 3 · choose 1

The AWS Trusted Advisor check Amazon S3 Bucket Permissions shows red for a bucket that holds internal reports. Its bucket policy allows public read access, and Block Public Access is not enabled on it. Staff read the reports only through IAM roles in the account. Which action stops the public access right away and takes the check out of red?

  1. ATurn on default encryption with AWS KMS keys for the bucket
  2. BTurn on S3 Versioning for the bucket
  3. CTurn on S3 server access logging for the bucket
  4. DTurn on all four Block Public Access settings
Show the answer and why
  • ATurn on default encryption with AWS KMS keys for the bucket

    Incorrect

    Encryption protects stored objects, but anyone the policy allows can still read them. S3 already encrypts new uploads by default.

  • BTurn on S3 Versioning for the bucket

    Incorrect

    Versioning keeps earlier versions of objects. It changes nothing about who can read them.

  • CTurn on S3 server access logging for the bucket

    Incorrect

    Access logs record requests, including public ones. They do not block any request.

  • DTurn on all four Block Public Access settings

    Correct

    Block Public Access overrides policies that grant public access, so the public can no longer read the reports. The check then shows yellow, not red, until the public statement is also removed from the bucket policy.

The check turns red when public access is allowed and Block Public Access is off. Full Block Public Access removes the public grant's effect while IAM access inside the account keeps working; deleting the public statement from the bucket policy is the clean-up that turns the check green.

Question 4 · choose 1

A company with 30 accounts in AWS Organizations must continuously check every member account against the same set of AWS Config rules, such as "EBS volumes are encrypted" and "security groups do not allow unrestricted SSH", with remediation actions attached. The security team wants to deploy and update the whole set centrally from one account. What should the team use?

  1. AAn organization conformance pack, deployed from the management account
  2. BThe same Config rules created by hand in each account's console
  3. CAn AWS CloudTrail organization trail that logs events from all accounts
  4. DAmazon Inspector turned on in all member accounts
Show the answer and why
  • AAn organization conformance pack, deployed from the management account

    Correct

    Conformance packs bundle Config rules and remediation actions, and AWS Config can deploy, update and delete them centrally across the member accounts of an organization.

  • BThe same Config rules created by hand in each account's console

    Incorrect

    Rules created account by account work, but nothing manages or updates them centrally, which is what the team asked for.

  • CAn AWS CloudTrail organization trail that logs events from all accounts

    Incorrect

    An organization trail logs API events for every account. It does not evaluate resource configurations against rules.

  • DAmazon Inspector turned on in all member accounts

    Incorrect

    Inspector scans workloads for software vulnerabilities and network exposure; it does not run Config rules.

A rule set with remediation, deployed as one unit across an organization, is an organization conformance pack.

Question 5 · choose 2

An account still has 40 IAM users who sign in to the AWS Management Console. An audit requires two controls: console passwords must be changed at least every 90 days, and the users must not be able to do anything except manage their own MFA device until they have signed in with MFA. Which actions meet these requirements? (Choose TWO.)

  1. AAttach an SCP to the account that sets a 90-day password expiration
  2. BCreate an IAM Access Analyzer unused access analyzer for the account
  3. CDownload the IAM credential report every 90 days and email it to the affected users
  4. DSet an account password policy with a password expiration period of 90 days
  5. EAttach a policy that denies all but MFA self-service actions when aws:MultiFactorAuthPresent is false
Show the answer and why
  • AAttach an SCP to the account that sets a 90-day password expiration

    Incorrect

    SCPs only set the maximum available permissions for users and roles. They never grant permissions and do not configure password rules.

  • BCreate an IAM Access Analyzer unused access analyzer for the account

    Incorrect

    An unused access analyzer reports unused access. It enforces neither password changes nor MFA.

  • CDownload the IAM credential report every 90 days and email it to the affected users

    Incorrect

    The credential report shows the status of passwords, access keys and MFA devices. It does not force anyone to act.

  • DSet an account password policy with a password expiration period of 90 days

    Correct

    The account password policy sets mandatory rotation periods for IAM users' passwords, and an expiration period takes effect immediately.

  • EAttach a policy that denies all but MFA self-service actions when aws:MultiFactorAuthPresent is false

    Correct

    AWS's example policy denies everything except managing one's own MFA device unless the request was authenticated with MFA.

Password rotation is an account password policy setting; "nothing without MFA" is a deny statement conditioned on aws:MultiFactorAuthPresent.

Practise domain 4 →Practise all domains →