QuestionQ13

Troubleshooting

A junior cloud administrator was recently promoted to cloud administrator and added to the cloud administrator group. This group is the only one authorized to access the engineering VM. After the promotion, the new administrator is unable to access the engineering VM, even though the other administrators in the same group can access it without any problems.

Which of the following is the best way to identify the root cause of this issue?

Explanation

Since other members of the cloud administrator group can successfully access the engineering VM, the network path, firewall rules, and VM availability are clearly not the problem. The issue is isolated to the newly promoted administrator's account, which strongly suggests a permissions or access-control configuration problem specific to that user—such as incomplete propagation of group membership, a conflicting explicit deny, or an incorrectly scoped role assignment. Reviewing the administrator's actual permissions on the engineering VM is the correct troubleshooting step because it directly examines whether the access control list or IAM policy properly reflects the user's new group membership, allowing the root cause to be identified and corrected without introducing unnecessary changes like rebooting the system, opening the firewall to the entire internet, or capturing network traffic (none of which address an access-control discrepancy).

Community Discussion

No comments yet. Be the first to start the discussion!