โ† All AWS Flashcard Decks

AWS Identity & Access Management Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 AWS Identity & Access Management flashcards as text
  1. Which IAM feature allows you to set the maximum permissions that identity-based policies can grant to an IAM entity?

    Answer: Permission boundaries

    Permission boundaries are managed policies that define the maximum permissions an IAM entity can have, regardless of what identity-based policies grant.

  2. An IAM role has a trust policy and a permissions policy. What does the trust policy define?

    Answer: Which principals are allowed to assume the role

    A trust policy defines which principals (users, roles, services, or accounts) are permitted to assume the IAM role via sts:AssumeRole.

  3. What is the purpose of an IAM instance profile?

    Answer: To attach an IAM role to an EC2 instance so applications can obtain temporary credentials

    An instance profile is a container for an IAM role that allows EC2 instances to retrieve temporary credentials via the instance metadata service.

  4. A developer needs temporary credentials scoped to specific S3 objects for a third-party application. Which approach is most appropriate?

    Answer: Use GetFederationToken with a scoped session policy

    GetFederationToken issues temporary credentials and accepts a session policy to further restrict permissions for the federated session.

  5. Which condition key in IAM policies allows you to restrict access based on the presence of MFA authentication?

    Answer: aws:MultiFactorAuthPresent

    The aws:MultiFactorAuthPresent condition key returns true when the request was authenticated using MFA, allowing you to enforce MFA for sensitive actions.

  6. What happens when both an identity-based policy and a resource-based policy apply to a request within the same AWS account?

    Answer: An explicit allow in either policy grants access

    Within the same account, if either the identity-based or resource-based policy grants the action and neither has an explicit deny, the action is allowed.

  7. Which IAM policy element specifies the AWS account, IAM user, IAM role, or federated user that a policy applies to in a resource-based policy?

    Answer: Principal

    The Principal element in a resource-based policy specifies who is allowed or denied access to the resource to which the policy is attached.