Enable IAM Access Analyzer for the organization with a zone of trust and filter by account

Answer Correct answer: A — enable IAM Access Analyzer for the organization with a zone of trust and filter findings by account.

A company uses an organization in AWS Organizations to manage hundreds of AWS accounts. Some of the accounts provide access to external AWS principals through cross-account IAM roles and Amazon S3 bucket policies. The company needs to identify which external principals have access to which accounts. Which solution will provide this information?

  1. Enable AWS Identity and Access Management Access Analyzer for the organization. Configure the organization as a zone of trust. Filter findings by AWS account ID. Correct Answer
  2. Create a custom AWS Config rule to monitor IAM roles in each account. Deploy an AWS Config aggregator to a central account. Filter findings by AWS account ID.
  3. Activate Amazon Inspector. Integrate Amazon Inspector with AWS Security Hub. Filter findings by AWS account ID for the IAM role resource type and the S3 bucket policy resource type.
  4. Configure the organization to use Amazon GuardDuty. Filter findings by AWS account ID for the Discovery:IAMUser/AnomalousBehavior finding type.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

IAM Access Analyzer is built exactly for this: it evaluates resource-based policies across accounts and reports external access, and an organization zone of trust scopes 'external' to outside the org. Filtering findings by account ID answers 'which external principal → which account.' Config aggregator (B) monitors config compliance, not external access; Inspector (C) scans vulnerabilities; GuardDuty (D) detects threats, not entitlement mapping. A is correct.

To discover which external principals have access to which accounts across a large organization, enable IAM Access Analyzer for the organization and define the organization as a zone of trust. Access Analyzer continuously analyzes resource policies (IAM roles, S3 bucket policies, etc.) and surfaces findings for any principal outside the zone of trust, which can be filtered by AWS account ID.

Using a Config aggregator (B)—it aggregates configuration/compliance data, not external-principal access analysis. Using Inspector (C) or GuardDuty (D)—those detect vulnerabilities and threats, not who holds cross-account access. Access Analyzer (A) is the entitlement-discovery service.

Community Discussion (4 comments)

cumzle_com 👍 2 Selected: A
Option A using AWS IAM Access Analyzer is the most suitable solution for identifying external principals (AWS accounts) with access to accounts managed within an AWS Organizations setup. It provides centralized and specific insights into cross-account access permissions, which aligns well with the company's requirement to track external access across multiple AWS accounts.
jade290 👍 3 Selected: A
AWS IAM Access Analyzer is a least privilege service that allows central review and removal of unused and external access across your AWS accounts with continuous monitoring. Reference: https://aws.amazon.com/iam/access-analyzer/
fibonacciname 👍 2 Selected: A
A is correct
mehmetsungur 👍 2
Option A is the most appropriate solution for identifying external principals' access to AWS accounts within an organization.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

IAM Access Analyzer continuously analyzes resource-based policies (IAM roles, S3 bucket policies, KMS, etc.) and generates findings for any principal outside the configured zone of trust. Enabling it for the organization with the org as the zone of trust identifies external access across all accounts, and findings can be filtered by account ID to map external principal to account.

Why the Other Options Are Wrong

B (Config aggregator) collects configuration/compliance state, not external-access entitlement analysis. C (Inspector) finds software vulnerabilities, and D (GuardDuty) finds threats/AnomalousBehavior—neither maps cross-account principal access. A is the purpose-built service for this question.

Community Comment Notes

Community voted A (100). Commenters described IAM Access Analyzer as the least-privilege service for continuous review of external access across an organization, referencing the zone-of-trust concept. A confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide