passdrill
AWS SAA-C03 · IAM & Security · Card 015/024 medium

A security team manages many AWS accounts under AWS Organizations and wants to identify, across every account, each S3 bucket, IAM role, and KMS key whose resource-based policy grants access to a principal outside their own accounts, without manually inspecting every resource policy by hand. Which service is designed for this?

  1. Amazon GuardDuty, which uses machine learning to detect anomalous account and network behavior from VPC Flow Logs, DNS query logs, and CloudTrail events
  2. AWS Config, which records configuration changes for supported resources over time and evaluates them against compliance rules
  3. IAM Access Analyzer, which defines a zone of trust for an account or organization and uses automated reasoning on resource-based policies to generate a finding whenever a resource is shared with a principal outside that zone
  4. AWS Trusted Advisor, which checks accounts against a fixed set of cost, performance, and security best-practice checks
Next card → Shuffle