Certified Solutions Architect IAM Policies and User Roles Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Solutions Architect IAM Policies and User Roles flashcards as text
A developer wants to allow an S3 bucket to be accessed only when the request comes through a specific VPC endpoint. Which condition key enforces this?
Answer: aws:SourceVpce
The aws:SourceVpce condition key restricts S3 bucket access to requests that originate from a specified VPC endpoint ID.
What is the default maximum number of IAM users that can be created in an AWS account?
Answer: 5000
AWS allows up to 5,000 IAM users per account by default, though this limit can be increased via a service quota request.
Which IAM managed policy grants an IAM user full access to all AWS services and resources?
Answer: AdministratorAccess
The AdministratorAccess managed policy provides full access to all AWS services and resources, equivalent to the root account for IAM purposes.
How does an IAM role differ from an IAM user regarding credential management?
Answer: Roles use temporary credentials that expire; users have long-term access keys
IAM roles provide temporary security credentials obtained via STS, while IAM users have long-term access keys that must be manually rotated.
A solutions architect needs to allow a third-party auditor to assume a role in their AWS account securely. What element in the role's trust policy helps prevent the confused deputy problem?
Answer: An 'ExternalId' condition in the trust policy
An ExternalId condition in the trust policy prevents the confused deputy attack by requiring the third party to provide a secret identifier when assuming the role.
Which AWS service provides centralized visibility into which IAM roles, users, and external entities have access to your AWS resources?
Answer: IAM Access Analyzer
IAM Access Analyzer analyzes resource-based policies and identifies resources shared with external entities, helping you find unintended access.
When using IAM Identity Center (SSO), how are permissions granted to users for AWS account access?
Answer: Through permission sets that are assigned to users or groups for specific accounts
IAM Identity Center uses permission sets, which are collections of policies, assigned to users or groups for specific AWS accounts in the organization.