Amazon
SOA-C02 · Question #398
A company's application currently uses an IAM role that allows all access to all AWS services. A SysOps administrator must ensure that the company's IAM policies allow only the permissions that the ap
Sign in or unlock SOA-C02 to reveal the answer and full explanation for question #398. The question stem and answer options stay visible for context.
Submitted by kevin_r· Mar 30, 2026Security and Compliance
Question
A company's application currently uses an IAM role that allows all access to all AWS services. A SysOps administrator must ensure that the company's IAM policies allow only the permissions that the application requires. How can the SysOps administrator create a policy to meet this requirement?
Options
- ATurn on AWS CloudTrail. Generate a policy by using AWS Security Hub.
- BTurn on Amazon EventBridge (Amazon CloudWatch Events). Generate a policy by using AWS
- CUse the AWS CLI to run the get-generated-policy command in AWS Identity and Access
- DTurn on AWS CloudTrail. Generate a policy by using AWS Identity and Access Management
Unlock SOA-C02 to see the answer
You've previewed enough free SOA-C02 questions. Unlock SOA-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#IAM policies#least privilege#IAM Access Analyzer#CloudTrail