โ† All AWS Flashcard Decks

AWS Security and IAM Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 AWS Security and IAM flashcards as text
  1. Which IAM policy evaluation logic applies when a resource-based policy grants access but an identity-based policy is silent on the action?

    Answer: Access is granted because resource-based policies take precedence

    When a resource-based policy grants access to an IAM principal in the same account, access is allowed even if the identity-based policy doesn't explicitly permit it.

  2. What is the purpose of an IAM Permission Boundary?

    Answer: It sets the maximum permissions an IAM entity can have regardless of attached policies

    A permissions boundary is a managed policy that sets the maximum permissions an identity-based policy can grant to an IAM entity.

  3. An EC2 instance needs to access S3 without embedding credentials. What is the recommended approach?

    Answer: Attach an IAM role to the EC2 instance

    Attaching an IAM role to an EC2 instance allows it to obtain temporary credentials automatically via the instance metadata service.

  4. Which AWS service provides centralized governance and policy management across multiple AWS accounts in an organization?

    Answer: AWS Organizations with SCPs

    AWS Organizations with Service Control Policies (SCPs) lets you centrally control the maximum available permissions across all accounts in your organization.

  5. What happens when an explicit Deny exists in any policy during IAM evaluation?

    Answer: It overrides all Allow statements and access is denied

    An explicit Deny in any applicable policy always overrides any Allow, regardless of the policy type or attached permissions.

  6. Which credential type should be used for programmatic access to AWS APIs from a long-running external application?

    Answer: IAM role with temporary credentials via STS AssumeRole

    Using STS AssumeRole provides temporary, automatically-rotated credentials, which is more secure than long-term IAM user access keys.

  7. A company wants to allow developers to create IAM roles but prevent them from granting more permissions than they themselves have. Which IAM feature enforces this?

    Answer: Permission Boundaries on the created roles

    Requiring developers to attach a permissions boundary when creating roles ensures the new roles cannot exceed the developer's own permission level.