nerdexam
Amazon

CLF-C02 · Question #3

Which AWS service or feature identifies whether an Amazon S3 bucket or an IAM role has been shared with an external entity?

The correct answer is C. AWS IAM Access Analyzer. AWS IAM Access Analyzer is purpose-built to continuously monitor resource policies and identify resources - such as S3 buckets, IAM roles, KMS keys, and Lambda functions - that have been shared with external entities (outside your AWS account or organization), helping you detect

Submitted by ahmad_uae· Mar 6, 2026Security and Compliance

Question

Which AWS service or feature identifies whether an Amazon S3 bucket or an IAM role has been shared with an external entity?

Options

  • AAWS Service Catalog
  • BAWS Systems Manager
  • CAWS IAM Access Analyzer
  • DAWS Organizations

How the community answered

(60 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    90% (54)
  • D
    5% (3)

Explanation

AWS IAM Access Analyzer is purpose-built to continuously monitor resource policies and identify resources - such as S3 buckets, IAM roles, KMS keys, and Lambda functions - that have been shared with external entities (outside your AWS account or organization), helping you detect unintended access. AWS Service Catalog (A) is used to manage and provision approved IT service portfolios, not to analyze resource sharing or external access. AWS Systems Manager (B) is an operations management service for managing infrastructure configuration, patching, and automation - it has no function related to detecting external resource sharing. AWS Organizations (D) helps centrally manage and govern multiple AWS accounts but does not analyze or identify whether specific resources like S3 buckets or IAM roles are exposed to external entities.

Memory Tip: Think of IAM Access Analyzer as a "security spotlight" - it analyzes who has access from the outside, making it easy to associate with the words in its name: Access + Analyzer = detecting external access.

Topics

#IAM Access Analyzer#Security#Resource Sharing#Access Control

Community Discussion

No community discussion yet for this question.

Full CLF-C02 Practice