nerdexam
Amazon

SCS-C02 · Question #114

A company needs to improve its ability to identify and prevent IAM policies that grant public access or cross-account access to resources. The company has implemented AWS Organizations and has…

The correct answer is A. Create an AWS Step Functions state machine that checks the resource type in the finding and C. In Amazon EventBridge, create an event rule that matches active IAM Access Analyzer findings F. Create an Amazon Simple Notification Service (Amazon SNS) topic for external or cross-account. https://aws.amazon.com/blogs/compute/orchestrating-a-security-incident-response-with-aws-

Submitted by omar99· Mar 6, 2026Identity and Access Management

Question

A company needs to improve its ability to identify and prevent IAM policies that grant public access or cross-account access to resources. The company has implemented AWS Organizations and has started using AWS Identity and Access Management Access Analyzer to refine overly broad access to accounts in the organization. A security engineer must automate a response in the company's organization for any newly created policies that are overly permissive. The automation must remediate external access and must notify the company's security team. Which combination of steps should the security engineer take to meet these requirements? (Choose three.)

Options

  • ACreate an AWS Step Functions state machine that checks the resource type in the finding and
  • BCreate an AWS Batch job that forwards any resource type findings to an AWS Lambda function.
  • CIn Amazon EventBridge, create an event rule that matches active IAM Access Analyzer findings
  • DIn Amazon CloudWatch, create a metric filter that matches active IAM Access Analyzer findings
  • ECreate an Amazon Simple Queue Service (Amazon SQS) queue. Configure the queue to forward
  • FCreate an Amazon Simple Notification Service (Amazon SNS) topic for external or cross-account

How the community answered

(45 responses)
  • A
    82% (37)
  • B
    4% (2)
  • D
    11% (5)
  • E
    2% (1)

Explanation

https://aws.amazon.com/blogs/compute/orchestrating-a-security-incident-response-with-aws-

Topics

#IAM Access Analyzer#EventBridge automation#Step Functions#overly permissive policies

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice