CommencerCommencez gratuitement

See implicit deny in action

You are on call this week. A scheduled function called report-archiver copies each morning's report into an archive bucket, and it has failed every day of your rotation. The team's first instinct was to attach a broader policy and move on.

Before anyone does that, use the AccessDenied investigator to work out which kind of denial this is. Run the function and read the failure, then open the role and read the evaluation trace.

Two denials produce this same message, and they need opposite fixes. Name the one you are looking at.

Cet exercice fait partie du cours

<cours>Using AWS Security for Developers</cours>
Voir le cours

Exercice interactif pratique

Transformez la théorie en action avec l’un de nos exercices interactifs

Commencer l’exercice