Certified Solutions Architect IAM Policies and User Roles Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Solutions Architect IAM Policies and User Roles flashcards as text
A company uses AWS Organizations and wants to prevent member accounts from leaving the organization. Which policy type can enforce this?
Answer: Service Control Policy (SCP) denying organizations:LeaveOrganization
An SCP that denies the organizations:LeaveOrganization action prevents member account administrators from removing their account from the organization.
What is the maximum session duration that can be configured for an IAM role assumed via the console?
Answer: 12 hours
IAM roles can be configured with a maximum session duration of up to 12 hours for console sessions and role assumptions.
Which IAM policy element specifies what actions are allowed or denied?
Answer: Action
The Action element in an IAM policy specifies the specific API actions that the policy allows or denies, such as s3:GetObject or ec2:RunInstances.
A user who has been granted PowerUserAccess tries to create a new IAM role. What will happen?
Answer: The action fails because PowerUserAccess excludes IAM management actions
PowerUserAccess explicitly denies IAM, Organizations, and Account actions, so users with this policy cannot create or modify IAM roles.
What is the difference between an AWS managed policy and a customer managed policy?
Answer: AWS managed policies are created and maintained by AWS; customer managed policies are created and maintained by you
AWS managed policies are predefined by AWS and updated automatically, while customer managed policies are created and controlled entirely by the AWS account owner.
An IAM policy uses 'Resource': '*' with 'Action': 'kms:Decrypt'. What is the security risk?
Answer: The policy allows decryption using any KMS key in the account, violating least privilege
Using a wildcard resource with KMS actions grants access to all keys in the account, which violates least privilege and could expose sensitive encrypted data.
Which STS API call is used by an EC2 instance to retrieve temporary credentials from an attached IAM role?
Answer: Credentials are automatically provided via the EC2 instance metadata service (IMDS)
EC2 instances with an attached IAM role automatically receive temporary credentials via the instance metadata service at 169.254.169.254 without explicitly calling STS.