Identity and Access Management Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Identity and Access Management flashcards as text
Which type of IAM policy is attached directly to IAM users, groups, or roles?
Answer: Identity-based policy
Identity-based policies are attached to IAM identities (users, groups, or roles) and define what actions those identities are permitted to perform.
What are IAM access keys used for?
Answer: Programmatic access to AWS services via CLI or SDK
IAM access keys (consisting of an access key ID and secret access key) are used for programmatic access to AWS through the CLI, SDK, or direct API calls.
Which IAM feature acts as a guardrail by setting the maximum permissions an IAM entity can ever receive?
Answer: Permissions Boundary
Permissions boundaries define the maximum permissions an IAM entity can be granted, even if attached policies would otherwise allow more.
Which statement about IAM groups is accurate?
Answer: A single IAM user can belong to multiple groups
An IAM user can be a member of multiple groups simultaneously, inheriting the combined permissions from all groups they belong to.
When an IAM policy contains both an explicit Allow and an explicit Deny for the same action, what is the result?
Answer: Deny takes precedence
In IAM, an explicit Deny always overrides any Allow, ensuring that denied permissions cannot be inadvertently granted by another policy.
Which AWS service generates temporary security credentials for federated users or applications assuming IAM roles?
Answer: AWS Security Token Service (STS)
AWS STS (Security Token Service) issues temporary security credentials that are used when entities assume IAM roles or when users authenticate through external identity providers.
What is the default maximum number of IAM users allowed per AWS account?
Answer: 5,000
AWS allows up to 5,000 IAM users per account by default, and this soft limit can be increased by submitting a service quota request.