Verify the SQS resource policy does not deny the role and that the role allows queue access

Answer Correct answer: B, E — verify the SQS resource policy does not deny the role and that the role allows the needed queue access.

An application has been built with Amazon EC2 instances that retrieve messages from Amazon SQS. Recently, IAM changes were made and the instances can no longer retrieve messages. What actions should be taken to troubleshoot the issue while maintaining least privilege? (Choose two.)

  1. Configure and assign an MFA device to the role used by the instances.
  2. Verify that the SQS resource policy does not explicitly deny access to the role used by the instances. Correct Answer
  3. Verify that the access key attached to the role used by the instances is active.
  4. Attach the AmazonSQSFullAccess managed policy to the role used by the instances.
  5. Verify that the role attached to the instances contains policies that allow access to the queue. Correct Answer

Community Votes

BE
100%

100% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

After IAM changes, the two likely causes are an explicit Deny in the SQS resource policy (B) or the role no longer having an Allow for queue access (E). Verifying both keeps least privilege—you do not add broad managed policies. MFA on the role (A) is unrelated to SQS retrieval; access keys (C) are not how EC2 instance roles authenticate; attaching SQSFullAccess (D) violates least privilege. B and E are correct.

EC2 instances stopped retrieving SQS messages after IAM changes. While keeping least privilege, troubleshoot by confirming the SQS queue resource policy does not contain an explicit Deny for the instance role, and confirming the role attached to the instances actually includes policies that allow the needed SQS actions. These two checks isolate whether the break is a resource-policy deny or a missing identity-policy grant.

Attaching AmazonSQSFullAccess (D)—that fixes access but violates the least-privilege requirement. Checking the role's access key (C)—instance roles use temporary credentials, not static access keys. Adding MFA to the role (A)—unrelated to why SQS reads fail. The right move is to verify the resource policy deny and the role's allow (B, E).

Community Discussion (3 comments)

Pat9595 👍 1 Selected: BE
B and E sounds right
IPLogic 👍 1 Selected: BE
To troubleshoot the issue while maintaining least privilege, you should: B. Verify that the SQS resource policy does not explicitly deny access to the role used by the instances. E. Verify that the role attached to the instances contains policies that allow access to the queue. These steps ensure that the IAM policies and resource policies are correctly configured without granting excessive permissions.
Bad_Mat 👍 1
Agree, BE

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

IAM changes can either introduce an explicit Deny in the SQS queue resource policy or remove the Allow from the instance role. Verifying the resource policy does not explicitly deny the role (B) and that the role still contains policies allowing the required SQS actions (E) pinpoints the cause without granting extra permissions—consistent with least privilege.

Why the Other Options Are Wrong

A configures MFA on the role, which does not affect SQS retrieval. C checks an access key, but EC2 instance roles use temporary credentials, not access keys. D attaches SQSFullAccess, which would work but breaks the least-privilege constraint. B and E are the correct troubleshooting steps.

Community Comment Notes

Community voted B,E (100). Commenters stated B (check the SQS resource policy for an explicit deny) and E (verify the role has allow policies for the queue) are the least-privilege troubleshooting steps. D was excluded as over-permissioned.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide