AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

A security engineer is investigating whether IAM policies within an AWS account unintentionally grant external accounts or public access to S3 buckets and IAM roles. Which AWS service can automatically analyze resource policies to identify this unintended external access?

  1. AAWS Config
  2. BAWS CloudTrail
  3. CAmazon Inspector
  4. DIAM Access Analyzer
Show answer & explanation

Correct answer: D. IAM Access Analyzer

IAM Access Analyzer uses logic-based reasoning to analyze resource policies (such as S3 bucket policies and IAM role trust policies) and identifies resources that are shared with an external entity, helping detect unintended public or cross-account access.

Why the other options are wrong

  • A. AWS Config tracks configuration compliance but does not perform this specific external-access policy analysis.
  • B. CloudTrail logs API activity but does not proactively analyze policies for external access risk.
  • C. Inspector scans for vulnerabilities, not policy-based external access.

IAM Access Analyzer

A service that analyzes resource policies to identify resources shared with external entities, helping detect unintended public or cross-account access.

  • Uses automated reasoning (mathematical logic) on policies
  • Analyzes S3, IAM roles, KMS keys, and more
  • Generates findings for external access, does not block it automatically

Memory trick: Access Analyzer 'peeks outside' your account boundary.

More Security and Compliance questions