AWS Identity & Access Management Flashcards
6 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 AWS Identity & Access Management flashcards as text
Which IAM Access Analyzer capability identifies AWS resources in your account that are accessible by external principals outside your organization?
Answer: IAM Access Analyzer Findings
IAM Access Analyzer scans resource-based policies and generates findings when resources like S3 buckets or IAM roles are accessible from outside the trust zone.
Which AWS service provides identity management and temporary credentials for mobile and web application end users?
Answer: Amazon Cognito
Amazon Cognito provides user pools for authentication and identity pools for granting temporary AWS credentials to app users.
Which IAM report lists all IAM users in an account along with the status of their passwords, access keys, and MFA devices?
Answer: IAM Credentials Report
The IAM Credentials Report is a downloadable CSV that shows the status of credentials for all IAM users, useful for security audits.
Which IAM policy type is created and managed by AWS, cannot be edited by customers, and covers common use cases?
Answer: AWS Managed Policy
AWS Managed Policies are created and maintained by AWS, updated automatically when services add new features, and cannot be modified by customers.
What is the maximum number of managed policies that can be attached to a single IAM user?
Answer: 10
AWS allows a maximum of 10 managed policies to be attached to a single IAM user, role, or group.
Which AWS service provides centralized storage and automatic rotation of database passwords and API keys for applications?
Answer: AWS Secrets Manager
AWS Secrets Manager stores, rotates, and manages retrieval of secrets like database credentials, with built-in Lambda-based rotation for supported services.