Identity and Access Management Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity and Access Management flashcards as text
What is the primary purpose of AWS IAM Identity Center (formerly AWS Single Sign-On)?
Answer: Centrally managing access for multiple AWS accounts and applications with SSO
IAM Identity Center provides centralized access management across multiple AWS accounts and business applications, enabling single sign-on for users.
Which of the following is an AWS best practice for managing IAM access keys?
Answer: Rotate access keys regularly and use IAM roles where possible instead of keys
AWS recommends rotating access keys regularly and preferring IAM roles over long-term access keys to reduce the risk of credential exposure.
What does the IAM Policy Simulator allow you to do?
Answer: Test the effects of IAM policies to see what actions they allow or deny
The IAM Policy Simulator lets you test and troubleshoot policies before applying them by simulating API calls and checking whether they would be allowed or denied.
Which type of policy is used with AWS Organizations to set the maximum available permissions for all accounts within an organization or organizational unit?
Answer: Service Control Policy (SCP)
Service Control Policies (SCPs) are applied at the AWS Organizations level to set guardrails on the maximum permissions available to accounts within an organization or OU.
What is the purpose of an IAM credential report?
Answer: To audit IAM users and the status of their credentials across the account
IAM credential reports provide a downloadable CSV listing all IAM users and the status of their passwords, access keys, and MFA devices, supporting security audits.
Which capability allows an IAM role in one AWS account to be assumed by a user or service in a different AWS account?
Answer: Cross-account role assumption
Cross-account role assumption allows an entity in one AWS account to assume an IAM role that belongs to a different account, enabling controlled cross-account access.
What is an IAM instance profile and what is it used for?
Answer: A container for an IAM role that can be attached to an EC2 instance to grant it AWS permissions
An instance profile is a container that passes an IAM role to an EC2 instance, allowing the instance to make AWS API calls with the role's permissions without using static credentials.