AnswerCorrect answer: A — log script activity in CloudTrail and use IAM Access Analyzer policy generation to produce a least-privilege policy.
A security engineer is designing an IAM policy for a script that will use the AWS CLI. The script currently assumes an IAM role that is attached to three AWS managed IAM policies: AmazonEC2FullAccess, AmazonDynamoDBFullAccess, and AmazonVPCFullAccess. The security engineer needs to construct a least privilege IAM policy that will replace the AWS managed IAM policies that are attached to this role. Which solution will meet these requirements in the MOST operationally efficient way?
In AWS CloudTrail, create a trail for management events. Run the script with the existing AWS managed IAM policies. Use IAM Access Analyzer to generate a new IAM policy that is based on access activity in the trail. Replace the existing AWS managed IAM policies with the generated IAM policy for the role. Correct Answer
Remove the existing AWS managed IAM policies from the role. Attach the IAM Access Analyzer Role Policy Generator to the role. Run the script. Return to IAM Access Analyzer and generate a least privilege IAM policy. Attach the new IAM policy to the role.
Create an account analyzer in IAM Access Analyzer. Create an archive rule that has a filter that checks whether the PrincipalArn value matches the ARN of the role. Run the script. Remove the existing AWS managed IAM policies from the role.
In AWS CloudTrail, create a trail for management events. Remove the existing AWS managed IAM policies from the role. Run the script. Find the authorization failure in the trail event that is associated with the script. Create a new IAM policy that includes the action and resource that caused the authorization failure. Repeat the process until the script succeeds. Attach the new IAM policy to the role.
Community Votes
A
100%
100% of anonymous learners picked answer A.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
IAM Access Analyzer policy generation consumes CloudTrail event history to synthesize a least-privilege policy from what the role actually did—the most operationally efficient path (A). Manually removing policies and iterating on authorization failures (D) is slow and error-prone. The 'Role Policy Generator' is not attached to a role (B), and an archive rule (C) only suppresses findings, it does not generate a policy. A is correct.
To replace three AWS managed full-access policies with a least-privilege policy most efficiently, record the script's actual API calls in a CloudTrail trail for management events, then use IAM Access Analyzer policy generation to produce a scoped policy from that observed access activity and attach it to the role. This avoids manually guessing permissions and yields a minimal policy with little operational effort.
Manually stripping policies and chasing authorization failures in CloudTrail (D)—works but is slow and brittle compared to automated generation. Attaching a 'Role Policy Generator' to the role (B)—policy generation is run from Access Analyzer, not attached as a resource. Using an archive rule (C)—that hides findings, it does not produce a least-privilege policy.
Community Discussion (3 comments)
IPLogic👍 1Selected: A
The most operationally efficient way to construct a least privilege IAM policy for the script is Option A: A. In AWS CloudTrail, create a trail for management events. Run the script with the existing AWS managed IAM policies. Use IAM Access Analyzer to generate a new IAM policy that is based on access activity in the trail. Replace the existing AWS managed IAM policies with the generated IAM policy for the role. AWS CloudTrail logs all API calls, which provides a comprehensive record of the actions performed by the script. IAM Access Analyzer can analyze these logs to automatically generate a least privilege policy based on the actual access patterns1. This minimizes the manual effort required to identify necessary permissions. This approach ensures that the new policy includes only the permissions that are actually used, adhering to the principle of least privilege.
VPNalumni👍 2
A https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-policy-generation.html
mikelord👍 2
Option A provides the most operationally efficient solution by leveraging AWS CloudTrail to log access activity and IAM Access Analyzer to automatically generate a least privilege policy based on that activity. This approach minimizes manual intervention and ensures that the resulting IAM policy grants only the permissions necessary for the script to function, adhering to the principle of least privilege.
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
By running the script with its current managed policies while a CloudTrail trail captures management events, IAM Access Analyzer can analyze that access activity and generate a least-privilege policy reflecting only the actions the script actually performed. Attaching the generated policy replaces the three full-access managed policies with minimal permissions—the most operationally efficient approach.
Why the Other Options Are Wrong
D removes the managed policies first and then iteratively fixes authorization failures from CloudTrail, which is slow and risky (the script breaks on each missing permission). B misstates how policy generation works—it is invoked from Access Analyzer, not attached to a role. C uses an archive rule that only suppresses findings and does not generate a policy. A is correct.
Community Comment Notes
Community voted A (100). Commenters described A as the most operationally efficient: CloudTrail logs access activity and Access Analyzer auto-generates a least-privilege policy from it, replacing the three full-access managed policies. A confirmed.