Q320.A company has multiple AWS accounts and manages these accounts with AWS Organizations. A developer was given IAM user credentials to access AWS resources. The developer should have read-only access to all Amazon S3 buckets in the account. Howeverwhen the developer tries to access the S3 buckets from the console they receive an access denied error message with no buckets listed.A solutions architect reviews the permissions and finds that the developer's IAM user is listed as having read-only access to allS3 buckets in the account.Which additional steps should the solutions architect take to troubleshoot the issue? (Select TWO.)
A.Check the bucket policies for all S3 buckets. B.Check the ACLs for all S3 buckets. C.Check the SCPs set at the organizational units (OUs). D.Check for the permissions boundaries set for the IAM user. E.Check if an appropriate IAM role is attached to the IAM user.正确答案CD