passdrill
AWS SAA-C03 · IAM & Security · Card 006/014 medium

An engineer in Account A needs temporary access to resources in Account B for a scheduled maintenance task. The security team wants the access to expire automatically after a short session rather than persist afterward. Which mechanism achieves this?

  1. Create a permanent IAM user in Account B and share its access keys with the engineer for the task
  2. Grant the engineer's Account A IAM user a resource-based policy directly on every resource in Account B
  3. Add the engineer's Account A user ARN to an IAM group inside Account B
  4. Have the engineer call AWS STS to assume an IAM role in Account B whose trust policy permits Account A, receiving temporary credentials that expire automatically
Next card → Shuffle