passdrill
AWS SAA-C03 · IAM & Security · Card 004/014 medium

A platform team lets application teams create their own IAM roles for their workloads, but wants a guarantee that none of those self-created roles can ever be granted IAM administrative permissions or access to one specific sensitive S3 bucket, no matter what identity-based policy an application team attaches later. Which IAM feature is designed for this?

  1. A service control policy attached directly to each application team's individual IAM role
  2. An IAM policy simulator report that a reviewer runs manually before every deployment
  3. A permissions boundary attached to the roles that caps their maximum possible permissions regardless of what identity-based policies are attached afterward
  4. A resource-based policy added to every future resource those roles might ever need to access
Next card → Shuffle