Scope S3 access per user with a session-tag condition and audit access with CloudTrail data events

Answer Correct answers: A, C — Use an Identity Center permission set scoped by a PrincipalTag condition and log S3 data events to CloudTrail, then query with Athena.

A company wants to create a single Amazon S3 bucket for its data scientists to store work-related documents. The company uses AWS IAM Identity Center to authenticate all users. A group for the data scientists was created. The company wants to give the data scientists access to only their own work. The company also wants to create monthly reports that show which documents each user accessed. Which combination of steps will meet these requirements? (Choose two.)

  1. Create a custom IAM Identity Center permission set to grant the data scientists access to an S3 bucket prefix that matches their username tag. Use a policy to limit access to paths with the ${aws:PrincipalTag/userName}/* condition. Correct Answer
  2. Create an IAM Identity Center role for the data scientists group that has Amazon S3 read access and write access. Add an S3 bucket policy that allows access to the IAM Identity Center role.
  3. Configure AWS CloudTrail to log S3 data events and deliver the logs to an S3 bucket. Use Amazon Athena to run queries on the CloudTrail logs in Amazon S3 and generate reports. Correct Answer
  4. Configure AWS CloudTrail to log S3 management events to CloudWatch. Use Amazon Athena’s CloudWatch connector to query the logs and generate reports.
  5. Enable S3 access logging to EMR File System (EMRFS). Use Amazon S3 Select to query logs and generate reports.

Community Votes

AC
100%

100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Scoping access per user means the authorization must be evaluated against a session attribute rather than a role, and only CloudTrail data events record the object-level reads, since S3 server access logs record requests but not the authenticated principal in a queryable form.

A company wants a single S3 bucket for work documents, authenticates all users through AWS IAM Identity Center, and has a data scientist group. Each data scientist must reach only their own work, and the company needs monthly reports showing which documents each user accessed.

Granting the group read and write on the whole bucket with a bucket policy that allows the role. Every data scientist would then reach every other user's documents, which is the opposite of the requirement. Enabling S3 access logging to EMRFS and querying with S3 Select also does not produce a per-user access report in the form needed.

Community Discussion (3 comments)

0b43291 👍 2 Selected: AC
By combining a custom IAM Identity Center permission set with path-based access control and CloudTrail logging with Athena querying, the company can achieve the desired access control and reporting requirements for the data scientists' work-related documents stored in the S3 bucket. The other options are either incorrect or do not fully meet the requirements: B. Creating an IAM Identity Center role with S3 read and write access and adding an S3 bucket policy would not provide the granular access control required to restrict each user to their own work. D. Configuring CloudTrail to log S3 management events to CloudWatch and using Athena's CloudWatch connector would not capture the necessary data events for generating reports on which documents each user accessed. E. Enabling S3 access logging to EMRFS and using S3 Select would not provide the necessary logging and reporting capabilities for this use case.
awsaz 👍 4 Selected: AC
A and C
mifune 👍 1 Selected: AC
IAM Identity Center permission + Amazon Athena to run queries on the CloudTrail logs in Amazon S3 and generate reports, answer A-C

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The per-user requirement is met by a custom IAM Identity Center permission set whose session policy grants S3 access only under a prefix that matches the user's own identity, using a condition on the PrincipalTag for the user name so the policy evaluates each session separately rather than granting the whole bucket, which is why A is correct. For the reporting requirement, the question asks which documents each user accessed, which means object-level read events attributed to an identity. AWS CloudTrail data events for S3 record those object-level operations including the principal, and delivering them to an S3 bucket allows Amazon Athena to query them with SQL and generate the monthly reports, which is why C is correct.

Why the Other Options Are Wrong

B: An Identity Center role with S3 read and write plus a bucket policy allowing that role gives every member of the data scientist group access to every document in the bucket, so no user is restricted to their own work and the first requirement fails entirely. D: CloudTrail management events record API calls such as bucket configuration changes, not S3 object reads, so they cannot answer which documents a user accessed. Athena's CloudWatch connector would be querying the wrong data source for object-level access. E: S3 access logging records requests at the bucket level and S3 Select queries object contents rather than log records, so neither mechanism produces a per-user, per-document access report from EMRFS, and EMRFS is an EMR file layer rather than an audit destination.

Community Comment Notes

The community voted 100 to 0 for A and C, and the top-voted comment explained the pairing, with a custom Identity Center permission set using path-based access control for the per-user restriction, and CloudTrail logging with Athena for the reporting. Another commenter confirmed the same reasoning, that the permission set plus Athena queries over the CloudTrail logs in S3 satisfies both halves.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide