Certified Solutions Architect IAM Policies and User Roles Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Solutions Architect IAM Policies and User Roles flashcards as text
A Lambda function needs to write logs to CloudWatch and read from DynamoDB. What is the BEST way to grant these permissions?
Answer: Create an IAM role with the required policies and attach it as the Lambda execution role
Lambda execution roles are IAM roles that grant the function permission to access AWS services, following the principle of least privilege.
What is the maximum number of IAM roles that can be assumed in a single role chaining session?
Answer: 5
AWS limits role chaining to a maximum of 5 role assumptions in a single session to prevent privilege escalation chains.
Which policy type can be used to set guardrails that restrict the maximum permissions available to all accounts in an AWS Organization?
Answer: Service Control Policies (SCPs)
SCPs are Organization policies that set the maximum permissions for member accounts, restricting what actions even the root user can perform.
An application running on ECS tasks needs to access Secrets Manager. What credential mechanism should be used?
Answer: Assign an IAM role as the ECS task role
The ECS task role is an IAM role that grants permissions to the containers within the task, providing temporary credentials without embedding secrets.
What condition key would you use in an IAM policy to require that requests come from a specific IP address range?
Answer: aws:SourceIp
The aws:SourceIp condition key restricts access based on the requester's IP address, allowing you to allow or deny requests from specific CIDR ranges.
Which IAM entity should you use to delegate access to AWS services on behalf of an AWS account, rather than assigning permissions to a person?
Answer: IAM Role
IAM roles are designed to be assumed by services, applications, or other AWS accounts rather than being permanently associated with a person.
What happens when an SCP in AWS Organizations denies an action, but an IAM policy in the member account explicitly allows it?
Answer: The SCP deny takes precedence and the action is blocked
SCPs act as guardrails that override IAM policies; an SCP deny blocks the action regardless of what any identity-based policy allows.