certslothcertsloth
DVA-C02/Topic 01

AWS / Associate

IAM & AWS CLI

5 min read5 recall promptsReviewed 2026-10-10

Memory hook: Identify who is calling, how they authenticated, and which policies authorize the exact request.

Must remember

Identities and credentials

  • The root user has special account-level capabilities. Protect it with MFA, avoid routine use, and do not create root access keys. Delegate ordinary administration; use root only when the specific operation requires it.
  • An IAM user is a persistent identity. Console passwords sign in to the console; access keys sign programmatic requests. These are different credentials.
  • An IAM group collects users and grants common permissions. Groups cannot contain other groups, are not shared logins and cannot be assumed like roles.
  • A role is an assumable identity issuing temporary credentials through AWS STS. Those credentials include an access key ID, secret key and session token, and expire.
  • Prefer federation/IAM Identity Center for workforce access and roles for applications. External SAML/OIDC identities can federate to appropriate AWS access; do not create a permanent IAM user for every workload.
  • A role's trust policy controls who can assume it; its permission policies control what the assumed identity can do. Cross-account role access needs appropriate caller authorization and target trust.
  • For EC2, an instance profile exposes the role to the instance. Lambda and other services use their own service-role arrangements; a role is not always an instance profile.

Read and evaluate a policy

  • A JSON policy contains Version and Statement; statements use Effect, Action, Resource and optional Condition. Resource policies also identify Principal. Sid is an optional statement label.
  • Version selects the policy language, not when the policy was last edited. Action identifies API capabilities; Resource identifies the affected ARN or wildcard where the action requires one.
  • Requests are implicitly denied without an applicable authorization. Explicit deny overrides allow. Conditions such as requiring secure transport determine whether a statement matches.
  • Identity policies and resource policies can participate together. Permissions boundaries, session policies and organization policies can restrict effective permissions; they do not make an otherwise unauthorized request universally allowed.
  • See advanced IAM for principal/session, boundary, SCP and cross-account nuances; “all Allows add together” is unsafe.

Authentication hygiene and evidence

  • MFA adds an authentication factor; it grants no permissions. A password policy controls IAM-user password requirements, not API key safety or federated identity-provider settings.
  • Prefer short-lived credentials and least privilege. Never embed permanent keys in source code, AMIs, user data or Terraform variables.
  • AWS CLI profiles select configuration and credentials. Environment variables or cached sessions can affect the actual caller; always distinguish intended profile from effective identity.
  • CloudShell runs a managed shell using the signed-in console identity. It is not automatically an administrator and does not bypass IAM.
  • Credential report: IAM-user credential status, password/key age and MFA information across the account.
  • Access Advisor: historical service access that helps identify overbroad permissions. Access Analyzer has different policy/resource-access analysis capabilities. History alone cannot prove a permission will never be needed.

Choose under exam pressure

Requirement or clue Decision and reason
EC2 application must read one S3 prefix Scoped instance role; no embedded keys
Employees need central multi-account login Federation/Identity Center with temporary access
Team of IAM users needs the same permissions IAM group with shared policies
Audit old or unused user credentials Credential report
Reduce unused service permissions Access Advisor plus workload requirements
Another account needs temporary access Trusted role with appropriate permissions
HTTPS required despite an identity Allow Matching explicit Deny blocks insecure requests

Traps

  • Authentication is not authorization. A valid login or API signature does not prove a requested action is allowed.
  • A policy grants nothing merely by existing. The identity attachment or resource relationship must make it applicable.
  • Display redaction is not secret protection. Local state and configuration can retain credential material even when the UI masks it.

Active recall

1. An EC2 application needs S3 access across restarts. Why is an instance role better than putting keys in user data?

The role supplies temporary, refreshed credentials through the instance profile. User data can expose long-lived secrets and creates manual rotation work. Scope permissions to required buckets/actions; the role does not justify broad administrator access.

2. An IAM policy allows GetObject but a bucket policy denies HTTP. Can a second Allow fix HTTP access?

No. The matching explicit deny wins. Use HTTPS or correct an incorrectly designed deny condition. Adding permissive policies cannot override an applicable deny.

3. A role trusts another account, but that account's user cannot assume it. What is missing from the investigation?

Check caller authorization for STS AssumeRole, the exact trusted principal and conditions, and any restrictive boundaries or organization policies. Trust alone does not establish every prerequisite for cross-account access.

4. A manager wants all staff to share one MFA-protected IAM user. Why is this weaker than individual federated identities?

Shared credentials weaken attribution, individual revocation and permission management. MFA does not restore per-person accountability. Federated identities preserve separate sessions while centralizing authentication and assignments.

5. Access Advisor shows a service unused for a month. Should its permission always be removed immediately?

Not automatically. It is evidence for review, but infrequent recovery, monthly operations or seasonal workflows may still require the permission. Compare actual requirements and remove unnecessary access deliberately, without confusing history with a guarantee.

Terraform anchor: Use jsonencode for policy documents, and treat policy resources, trust relationships and attachments as separate parts of the authorization graph.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.