Section 4: IAM & AWS CLI Flashcards

(20 cards)

1
Q

What does IAM stand for?

A

identity and access management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What can groups contain?

A

only users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a policy?

A

a json set of rules that defines permissions for users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Is IAM region specific?

A

no, it is global

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What do policies belong to?

A

groups and users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the policy structure?

A

version
id
statement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the policy statement structure?

A

sid (optional)
effect
principal
action
resource
condition (optional)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is effect in a policy statement?

A

allow or deny access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is principal in a policy statement?

A

states users to which this policy applied to

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is action in a policy statement?

A

the actions that the policy allows or denies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is condition in a policy statement?

A

condition when the policy will take effect
(works like an if statement with key-value pairs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is resource in a policy statement?

A

the resources the effect can use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a password policy?

A

admin setup password rules (i.e. how many characters and how often you need to change them) as well as MFA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is CloudShell?

A

AWS cloud based terminal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is an IAM Role?

A

a set of permissions for an entity to interact with AWS services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the two types of IAM security tools?

A

credentials report and last accessed

17
Q

What does the credentials report show?

A

shows all user activity across the whole account

18
Q

What does last accessed show?

A

shows which services the user has been accessing

19
Q

What is AWS responsible for in the Shared Responsibility Model?

A

infrastructure (global security)
configuration and vulnerability
compliance validation
(Everything platform related)

20
Q

What are you responsible for in the Shared Responsibility Model?

A

users/group permissions
MFA
rotating keys
reviewing permissions