AWS Identity & Access Management Flashcards
6 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 AWS Identity & Access Management flashcards as text
Which AWS Security Token Service feature issues temporary security credentials to users authenticated by an external identity provider?
Answer: AssumeRoleWithWebIdentity
AssumeRoleWithWebIdentity allows users authenticated by web identity providers like Amazon, Google, or Facebook to receive temporary AWS credentials.
Which AWS service provides a hierarchical structure to centrally manage multiple AWS accounts, apply governance policies, and consolidate billing?
Answer: AWS Organizations
AWS Organizations lets you group accounts into organizational units (OUs) and apply Service Control Policies for centralized governance.
What is the maximum session duration that can be configured when assuming an IAM role?
Answer: 12 hours
IAM role session durations can be set up to 12 hours (43,200 seconds) when the role's maximum session duration is configured accordingly.
Which AWS service issues and manages SSL/TLS certificates for use with AWS services and provides automatic renewal?
Answer: AWS Certificate Manager
AWS Certificate Manager (ACM) provisions, manages, and auto-renews public and private SSL/TLS certificates for use with AWS services.
What IAM Condition key can enforce MFA authentication before allowing access to sensitive API operations?
Answer: aws:MFAPresent
The condition key `aws:MultiFactorAuthPresent` (commonly shortened as MFAPresent) can be used in IAM policies to require MFA for sensitive operations.
Which type of IAM policy is embedded directly within a single IAM user, group, or role and is not reusable?
Answer: Inline Policy
Inline policies are created and embedded directly in an IAM identity; they are deleted when that identity is deleted and cannot be attached to other identities.