ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 276 - SCS-C02 discussion

Report
Export

A company has contracted with a third party to audit several AWS accounts. To enable the audit, cross- account IAM roles have been created in each account targeted for audit. The Auditor is having trouble accessing some of the accounts.

Which of the following may be causing this problem? (Choose three.)

A.
The external ID used by the Auditor is missing or incorrect.
Answers
A.
The external ID used by the Auditor is missing or incorrect.
B.
The Auditor is using the incorrect password.
Answers
B.
The Auditor is using the incorrect password.
C.
The Auditor has not been granted sts:AssumeRole for the role in the destination account.
Answers
C.
The Auditor has not been granted sts:AssumeRole for the role in the destination account.
D.
The Amazon EC2 role used by the Auditor must be set to the destination account role.
Answers
D.
The Amazon EC2 role used by the Auditor must be set to the destination account role.
E.
The secret key used by the Auditor is missing or incorrect.
Answers
E.
The secret key used by the Auditor is missing or incorrect.
F.
The role ARN used by the Auditor is missing or incorrect.
Answers
F.
The role ARN used by the Auditor is missing or incorrect.
Suggested answer: A, C, F

Explanation:

The following may be causing the problem for the Auditor:

A) The external ID used by the Auditor is missing or incorrect. This is a possible cause, because the external ID is a unique identifier that is used to establish a trust relationship between the accounts. The external ID must match the one that is specified in the role's trust policy in the destination account1.

C) The Auditor has not been granted sts:AssumeRole for the role in the destination account. This is a possible cause, because sts:AssumeRole is the API action that allows the Auditor to assume the cross-account role and obtain temporary credentials. The Auditor must have an IAM policy that allows them to call sts:AssumeRole for the role ARN in the destination account2.

F) The role ARN used by the Auditor is missing or incorrect. This is a possible cause, because the role ARN is the Amazon Resource Name of the cross-account role that the Auditor wants to assume. The role ARN must be valid and exist in the destination account3.

asked 16/09/2024
Amy Sukkar
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first