Identity and Access Management Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Identity and Access Management flashcards as text
What is the primary purpose of AWS Identity and Access Management (IAM)?
Answer: To control who can access AWS services and what actions they can perform
IAM is used to manage authentication and authorization, controlling which users and services can access AWS resources and what actions they can take.
Which IAM entity should be used to grant permissions to an AWS service such as EC2 to access S3?
Answer: IAM Role
IAM Roles are designed to grant permissions to AWS services so they can interact with other AWS services without requiring long-term credentials.
What is the AWS best practice recommendation for the root account?
Answer: Enable MFA and avoid using it for everyday tasks
AWS recommends enabling MFA on the root account and reserving its use only for tasks that specifically require root-level access.
What is an IAM policy?
Answer: A JSON document that defines allowed or denied actions on AWS resources
IAM policies are JSON documents specifying which actions are allowed or denied on which AWS resources, and they are attached to IAM identities or resources.
Which of the following is NOT a valid IAM identity type?
Answer: Permission
IAM identity types are Users, Groups, and Roles; Permission is not an identity but rather something granted to identities through policies.
What does the principle of least privilege mean in the context of AWS IAM?
Answer: Granting only the minimum permissions necessary to perform a required task
The principle of least privilege means assigning only the permissions users need to do their jobs, reducing the attack surface and potential for misuse.
Which AWS feature requires users to provide a second form of authentication in addition to a password?
Answer: Multi-Factor Authentication (MFA)
MFA adds an extra layer of security by requiring a second authentication factor (such as a one-time code) beyond the username and password.