Scope S3 access per user with a session-tag condition and audit access with CloudTrail data events
A company wants to create a single Amazon S3 bucket for its data scientists to store work-related documents. The company uses AWS IAM Identity Center to authenticate all users. A group for the data scientists was created. The company wants to give the data scientists access to only their own work. The company also wants to create monthly reports that show which documents each user accessed. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Scoping access per user means the authorization must be evaluated against a session attribute rather than a role, and only CloudTrail data events record the object-level reads, since S3 server access logs record requests but not the authenticated principal in a queryable form.
A company wants a single S3 bucket for work documents, authenticates all users through AWS IAM Identity Center, and has a data scientist group. Each data scientist must reach only their own work, and the company needs monthly reports showing which documents each user accessed.
Granting the group read and write on the whole bucket with a bucket policy that allows the role. Every data scientist would then reach every other user's documents, which is the opposite of the requirement. Enabling S3 access logging to EMRFS and querying with S3 Select also does not produce a per-user access report in the form needed.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The per-user requirement is met by a custom IAM Identity Center permission set whose session policy grants S3 access only under a prefix that matches the user's own identity, using a condition on the PrincipalTag for the user name so the policy evaluates each session separately rather than granting the whole bucket, which is why A is correct. For the reporting requirement, the question asks which documents each user accessed, which means object-level read events attributed to an identity. AWS CloudTrail data events for S3 record those object-level operations including the principal, and delivering them to an S3 bucket allows Amazon Athena to query them with SQL and generate the monthly reports, which is why C is correct.Why the Other Options Are Wrong
B: An Identity Center role with S3 read and write plus a bucket policy allowing that role gives every member of the data scientist group access to every document in the bucket, so no user is restricted to their own work and the first requirement fails entirely. D: CloudTrail management events record API calls such as bucket configuration changes, not S3 object reads, so they cannot answer which documents a user accessed. Athena's CloudWatch connector would be querying the wrong data source for object-level access. E: S3 access logging records requests at the bucket level and S3 Select queries object contents rather than log records, so neither mechanism produces a per-user, per-document access report from EMRFS, and EMRFS is an EMR file layer rather than an audit destination.Community Comment Notes
The community voted 100 to 0 for A and C, and the top-voted comment explained the pairing, with a custom Identity Center permission set using path-based access control for the per-user restriction, and CloudTrail logging with Athena for the reporting. Another commenter confirmed the same reasoning, that the permission set plus Athena queries over the CloudTrail logs in S3 satisfies both halves.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →