- Home
- All questions
- Question 12
AWS Certified Solutions Architect study material · question 12 of 500
An auditor asks which S3 buckets and IAM roles are reachable from outside the account. Which service reports that exposure?
Show the answer
Answer: A. IAM Access Analyzer
IAM Access Analyzer surfaces resources reachable publicly or from outside the account, which is how unintended sharing is discovered.
Source: Security best practices in IAM (Amazon Web Services) — Verify public and cross-account access with IAM Access Analyzer