nerdexam
Amazon

SOA-C02 · Question #398

A company's application currently uses an IAM role that allows all access to all AWS services. A SysOps administrator must ensure that the company's IAM policies allow only the permissions that the…

The correct answer is D. Turn on AWS CloudTrail. Generate a policy by using AWS Identity and Access Management. https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html#what-is- access-analyzer-policy-generation

Submitted by kevin_r· Mar 30, 2026Security and Compliance

Question

A company's application currently uses an IAM role that allows all access to all AWS services. A SysOps administrator must ensure that the company's IAM policies allow only the permissions that the application requires. How can the SysOps administrator create a policy to meet this requirement?

Options

  • ATurn on AWS CloudTrail. Generate a policy by using AWS Security Hub.
  • BTurn on Amazon EventBridge (Amazon CloudWatch Events). Generate a policy by using AWS
  • CUse the AWS CLI to run the get-generated-policy command in AWS Identity and Access
  • DTurn on AWS CloudTrail. Generate a policy by using AWS Identity and Access Management

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    17% (3)
  • C
    6% (1)
  • D
    72% (13)

Explanation

https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html#what-is- access-analyzer-policy-generation

Topics

#IAM policies#least privilege#IAM Access Analyzer#CloudTrail

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice