Certified Solutions Architect IAM Policies and User Roles Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Certified Solutions Architect IAM Policies and User Roles flashcards as text
Which IAM policy element is evaluated FIRST when AWS determines whether to allow or deny a request?
Answer: Explicit deny in any policy
An explicit Deny in any applicable policy always overrides any Allow, making it the highest-priority evaluation result.
A company wants to grant an EC2 instance access to S3 without embedding credentials. What is the recommended approach?
Answer: Attach an IAM role to the EC2 instance
Attaching an IAM role to an EC2 instance provides temporary credentials via the instance metadata service, eliminating the need for long-term credentials.
What does the IAM policy condition key 'aws:RequestedRegion' allow you to do?
Answer: Restrict actions to specific AWS regions
The aws:RequestedRegion condition key lets you restrict which AWS regions a principal can make API calls to.
Which type of IAM policy is attached directly to AWS resources such as S3 buckets and KMS keys?
Answer: Resource-based policy
Resource-based policies are JSON policy documents attached directly to a resource and specify who has access to that resource.
An IAM user in Account A needs to access resources in Account B. What must be configured in Account B?
Answer: A cross-account IAM role with a trust policy allowing Account A
Cross-account access requires an IAM role in Account B with a trust policy that allows principals from Account A to assume it.
What is the purpose of an IAM permissions boundary?
Answer: It sets the maximum permissions an IAM entity can have regardless of other policies
A permissions boundary is a managed policy that sets the maximum permissions an identity-based policy can grant to an IAM entity.
Which IAM feature allows you to test the effect of IAM policies before applying them in production?
Answer: IAM Policy Simulator
The IAM Policy Simulator lets you test and troubleshoot identity-based and resource-based policies to understand what actions are allowed or denied.