Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SCS-C03 Exam - Topic 4 Question 13 Discussion

AWS Config cannot deliver configuration snapshots to Amazon S3.Which TWO actions will remediate this issue?
A) Verify the S3 bucket policy allows config.amazonaws.com. and B) Verify the IAM role has s3:GetBucketAcl and s3:PutObject permissions.
C) Verify the S3 bucket can assume the IAM role.
D) Verify IAM policy allows AWS Config to write logs.
E) Modify AWS Config API permissions.

Amazon SCS-C03 Exam - Topic 4 Question 13 Discussion

Actual exam question for Amazon's SCS-C03 exam
Question #: 13
Topic #: 4
[All SCS-C03 Questions]

AWS Config cannot deliver configuration snapshots to Amazon S3.

Which TWO actions will remediate this issue?

Show Suggested Answer Hide Answer
Suggested Answer: A, B

AWS Config requires permissions at two levels to deliver configuration data: the AWS Config service role and the S3 bucket policy. The AWS Certified Security -- Specialty Study Guide states that the S3 bucket policy must explicitly allow the config.amazonaws.com service principal to write objects. Additionally, the IAM role used by AWS Config must allow s3:GetBucketAcl and s3:PutObject.

If either permission is missing, AWS Config cannot deliver snapshots and will log delivery errors in CloudTrail. This dual-permission model ensures least privilege while maintaining secure delivery of compliance data.

Other options reference incorrect principals or irrelevant permissions.

Referenced AWS Specialty Documents:

AWS Certified Security -- Specialty Official Study Guide

AWS Config Prerequisites


Contribute your Thoughts:

0/2000 characters
S3 bucket policy is crucial for access.
upvoted 0 times
...
Trinidad
5 days ago
Why A?
upvoted 0 times
...
Brande
10 days ago
I think A and B are the right choices.
upvoted 0 times
...
Rosio
15 days ago
This question is tricky.
upvoted 0 times
...
Lashanda
21 days ago
Not sure about D), isn't that more for logging than snapshots?
upvoted 0 times
...
Patria
26 days ago
Totally agree with A) and B), those are essential checks.
upvoted 0 times
...
Eura
1 month ago
Surprised that AWS Config can't send snapshots to S3 directly!
upvoted 0 times
...
Dominque
1 month ago
I think C) is a bit off, the bucket can't assume roles.
upvoted 0 times
...
Jettie
1 month ago
A) and B) are definitely the right moves!
upvoted 0 times
...
Colton
2 months ago
Not sure about E), seems like overkill for this issue.
upvoted 0 times
...
Hoa
2 months ago
D) is important for logging, but not for snapshots.
upvoted 0 times
...
Eden
2 months ago
Surprised that AWS Config can't send snapshots to S3!
upvoted 0 times
...
Corinne
2 months ago
I thought C) was necessary too?
upvoted 0 times
...
Dewitt
2 months ago
A) and B) are definitely the right moves!
upvoted 0 times
...
Tuyet
2 months ago
I think option D could be related, but I’m not sure if it directly affects the delivery of configuration snapshots. I need to double-check that.
upvoted 0 times
...
Stephane
3 months ago
I vaguely recall something about IAM roles and S3 permissions, but I can't remember if option C is relevant here. It seems a bit off to me.
upvoted 0 times
...
Yan
3 months ago
I'm not entirely sure, but I feel like option B is also important because the IAM role needs the right permissions to interact with S3.
upvoted 0 times
...
Horace
3 months ago
I think option A makes sense since the S3 bucket policy needs to allow access from AWS Config. I remember that from the practice questions.
upvoted 0 times
...

Save Cancel