โ† All AWS Flashcard Decks

AWS Identity & Access Management Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 AWS Identity & Access Management flashcards as text
  1. An organization uses AWS Organizations. Which policy type can be used to restrict the maximum available permissions for all accounts within an organizational unit (OU)?

    Answer: Service control policies (SCPs)

    SCPs in AWS Organizations set guardrails on the maximum permissions available to IAM entities in member accounts, acting as organization-level permission boundaries.

  2. What is the effect of attaching the AWS managed policy 'ReadOnlyAccess' to an IAM role while also attaching a customer-managed policy that explicitly denies s3:GetObject?

    Answer: The explicit deny in the customer policy overrides the allow, blocking S3 GetObject

    An explicit Deny in any applicable policy always overrides any Allow, so the customer-managed policy's deny blocks S3 GetObject access regardless of ReadOnlyAccess.

  3. Which AWS STS API call is used by an IAM user to assume a cross-account role?

    Answer: sts:AssumeRole

    sts:AssumeRole is used to obtain temporary security credentials for a role in the same or a different AWS account.

  4. A company wants to allow employees to sign in to AWS using their corporate Active Directory credentials without creating IAM users. Which solution should they use?

    Answer: AWS IAM Identity Center (SSO) with AD Connector or AWS Managed Microsoft AD

    AWS IAM Identity Center integrates with AWS Managed Microsoft AD or AD Connector to provide SSO access to AWS accounts using existing corporate credentials.

  5. Which IAM policy condition operator would you use to match a tag value against multiple possible values using a single condition?

    Answer: ForAnyValue:StringEquals

    ForAnyValue:StringEquals is a set operator that returns true if any value in a multivalued request context key matches any value in the condition.

  6. What is the default behavior of IAM when no policy grants access to a requested action?

    Answer: Deny, because IAM uses an implicit deny by default

    IAM uses an implicit deny as its default; requests are denied unless an explicit allow exists and no explicit deny overrides it.

  7. A Lambda function needs read access to a specific DynamoDB table. What is the recommended way to grant this access?

    Answer: Attach an IAM execution role with a policy allowing DynamoDB read actions to the Lambda function

    Assigning an IAM execution role to the Lambda function allows it to automatically receive temporary credentials with the necessary DynamoDB permissions without storing long-term credentials.