AWS Security and IAM Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 AWS Security and IAM flashcards as text
Which IAM policy evaluation logic applies when a resource-based policy grants access but an identity-based policy is silent on the action?
Answer: Access is granted because resource-based policies take precedence
When a resource-based policy grants access to an IAM principal in the same account, access is allowed even if the identity-based policy doesn't explicitly permit it.
What is the purpose of an IAM Permission Boundary?
Answer: It sets the maximum permissions an IAM entity can have regardless of attached policies
A permissions boundary is a managed policy that sets the maximum permissions an identity-based policy can grant to an IAM entity.
An EC2 instance needs to access S3 without embedding credentials. What is the recommended approach?
Answer: Attach an IAM role to the EC2 instance
Attaching an IAM role to an EC2 instance allows it to obtain temporary credentials automatically via the instance metadata service.
Which AWS service provides centralized governance and policy management across multiple AWS accounts in an organization?
Answer: AWS Organizations with SCPs
AWS Organizations with Service Control Policies (SCPs) lets you centrally control the maximum available permissions across all accounts in your organization.
What happens when an explicit Deny exists in any policy during IAM evaluation?
Answer: It overrides all Allow statements and access is denied
An explicit Deny in any applicable policy always overrides any Allow, regardless of the policy type or attached permissions.
Which credential type should be used for programmatic access to AWS APIs from a long-running external application?
Answer: IAM role with temporary credentials via STS AssumeRole
Using STS AssumeRole provides temporary, automatically-rotated credentials, which is more secure than long-term IAM user access keys.
A company wants to allow developers to create IAM roles but prevent them from granting more permissions than they themselves have. Which IAM feature enforces this?
Answer: Permission Boundaries on the created roles
Requiring developers to attach a permissions boundary when creating roles ensures the new roles cannot exceed the developer's own permission level.