Study. uk . com
  1. Home
  2. All questions
  3. Question 11

AWS Certified Solutions Architect study material · question 11 of 500

A security team wants to generate a least-privilege policy for a role from the activity that role has actually performed. Which service produces it?

  1. AWS Config
  2. IAM Access Analyzer
  3. Amazon Inspector
  4. Amazon Macie
Show the answer

Answer: B. IAM Access Analyzer

IAM Access Analyzer drafts a least-privilege policy from observed access activity and can also validate policies for correctness.

Source: Security best practices in IAM (Amazon Web Services) — Use IAM Access Analyzer to generate least-privilege policies

Challenge yourself on this topic → Study as cards