nerdexam
Amazon

SCS-C02 · Question #183

A company uses an organization in AWS Organizations to manage hundreds of AWS accounts. Some of the accounts provide access to external AWS principals through cross-account IAM roles and Amazon S3 buc

The correct answer is A. Enable AWS Identity and Access Management Access Analyzer for the organization. Configure. See the full explanation below for the reasoning.

Submitted by haruto_sh· Mar 6, 2026Identity and Access Management

Question

A company uses an organization in AWS Organizations to manage hundreds of AWS accounts. Some of the accounts provide access to external AWS principals through cross-account IAM roles and Amazon S3 bucket policies. The company needs to identify which external principals have access to which accounts. Which solution will provide this information?

Options

  • AEnable AWS Identity and Access Management Access Analyzer for the organization. Configure
  • BCreate a custom AWS Config rule to monitor IAM roles in each account. Deploy an AWS Config
  • CActivate Amazon Inspector. Integrate Amazon Inspector with AWS Security Hub. Filter findings by
  • DConfigure the organization to use Amazon GuardDuty. Filter findings by AWS account ID for the

How the community answered

(38 responses)
  • A
    71% (27)
  • B
    5% (2)
  • C
    8% (3)
  • D
    16% (6)

Topics

#IAM Access Analyzer#AWS Organizations#External Access#Resource Policies

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice