Security, Identity, and Compliance
CoreAWS IAM Access Analyzer
Explicit access auditing/troubleshooting evidence source.
Key points
- Access Analyzer surfaces supported external or unused access findings and policy issues for authorization review.
Best-known use cases
- D4.1, D4.2, and D5.1: investigate the named access finding and correct the responsible policy or trust boundary.
What candidates often confuse it with
- Access Analyzer identifies access findings; CloudTrail records past API calls and policy simulation predicts supported evaluations.
Key takeaway
Use the finding to locate the exact policy and principal rather than granting or revoking access broadly.
Related services
- AWS Certificate Manager (ACM)
- Amazon EC2 security groups
- Egress-only internet gateways
Relevant exam tasks
- D4.1 — Task 4.1: Implement and manage security and compliance tools and policies.
- 4.1.1 — Implement IAM features (for example, password policies, multi-factor authentication [MFA], roles, federated identity, resource policies, policy conditions).
- D4.2 — Task 4.2: Implement strategies to protect data and infrastructure.
- 4.2.1 — Implement and enforce a data classification scheme.
- D5.1 — Task 5.1: Implement and optimize networking features and connectivity.
- 5.1.1 — Configure a VPC (for example, subnets, route tables, network ACLs, security groups, NAT gateways, internet gateway, egress-only internet gateway).