- Home
- All questions
- Question 11
AWS Certified Solutions Architect study material · question 11 of 500
A security team wants to generate a least-privilege policy for a role from the activity that role has actually performed. Which service produces it?
Show the answer
Answer: B. IAM Access Analyzer
IAM Access Analyzer drafts a least-privilege policy from observed access activity and can also validate policies for correctness.
Source: Security best practices in IAM (Amazon Web Services) — Use IAM Access Analyzer to generate least-privilege policies