IAM Flashcards

1
Q

IAM JSON policy documents are composed of what elements?

A

Effect
Action
Resource
Condition (optional)
Principal (optional)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

IAM policy Effect does what?

A

Allow or Deny action(s) on resource(s)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

IAM policy Action does what?

A

Describes the specific API action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Whatis an IAM policy Resource?

A

Specifies the object or objects using the Amazon Resource Name (ARN) format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IAM policy Condition is?

A

Specifies conditions for the policy to be in effect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an IAM policy Principal?

A

Specifies the entity (account, user, role or service) that is allowed or denied access to a resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are SCPs and where are they applied?

A

Service Control Policies (SCP) specify the maximum permissions that the accounts administrator can delegate to the IAM users and roles in the affected accounts and is applied to an account, OU or organisational root.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the difference between SCPs and permission boundaries?

A

A permission boundary does not provide permissions but sets the maximum permissions and is assigned to an IAM entity. SCPs are hierarchical and are applied to the entire organisation or to OUs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does IAM Access Analyzer provide?

A

A report that identifies access to your resources from outside of the organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly