See implicit deny in action
You are on call this week. A scheduled function called report-archiver copies each morning's report into an archive bucket, and it has failed every day of your rotation. The team's first instinct was to attach a broader policy and move on.
Before anyone does that, use the AccessDenied investigator to work out which kind of denial this is. Run the function and read the failure, then open the role and read the evaluation trace.
Two denials produce this same message, and they need opposite fixes. Name the one you are looking at.
Bài tập này là một phần của khóa học
Using AWS Security for Developers
Bài tập tương tác thực hành
Biến lý thuyết thành hành động với một trong các bài tập tương tác của chúng tôi
Bắt đầu bài tập