开始使用免费开始使用

See implicit deny in action

You are on call this week. A scheduled function called report-archiver copies each morning's report into an archive bucket, and it has failed every day of your rotation. The team's first instinct was to attach a broader policy and move on.

Before anyone does that, use the AccessDenied investigator to work out which kind of denial this is. Run the function and read the failure, then open the role and read the evaluation trace.

Two denials produce this same message, and they need opposite fixes. Name the one you are looking at.

本练习是课程的一部分

Using AWS Security for Developers

查看课程

动手互动练习

通过我们的互动练习之一,将理论转化为实践

开始练习