skip to content

IAM & Security

IAM is where AWS interviews get uncomfortable, because the model has layers: identity versus resource policies, assume-role and temporary credentials, permission boundaries, organization SCPs, and Cognito for end users. You learn how a request is really evaluated, so least privilege becomes something you can design rather than recite.

part ofAWSoverview, primer and where to startread it →
on this pageshow

explore

questions

69 · 14 sections

Walk through the elements of an AWS IAM policy statement — Effect, Action, Resource, Condition and Principal — and explain why Principal appears in some IAM policies but not others.

level: juniorimportance: must knowfreq 82%
basics
~20 s

An IAM policy statement combines Effect (Allow or Deny), Action, Resource ARNs and an optional Condition. Principal appears only in resource-based policies, because an identity-based policy is already attached to the principal it applies to.

open as a page

In AWS IAM, when should a permission live in an identity-based policy attached to a user or role, and when does it have to live in a resource-based policy attached to the resource itself?

level: middleimportance: must knowfreq 66%
basics
~20 s

Identity-based policies are the default and scale per principal. A resource-based policy is required when the caller is outside the account, when an AWS service principal must be granted access, or when a rule must apply to every caller of that one resource.

open as a page

In AWS IAM, what is the difference between an AWS managed policy, a customer managed policy and an inline policy, and how do you choose between them?

level: middleimportance: should knowfreq 52%
basics
~20 s

Managed policies are standalone objects with an ARN that attach to many principals and keep prior versions; AWS managed ones are maintained by AWS and usually too broad. Inline policies are embedded in a single principal, have no ARN, and are deleted with it.

open as a page

You add a Deny statement to an AWS IAM policy with a Condition using StringEquals on a request context key, and it denies nothing. Why can an absent context key make a statement silently not apply, and what do the IfExists operator suffix and the Null operator do about it?

level: seniorimportance: should knowfreq 45%
basics
~20 s

IAM condition keys exist only if the request actually carries them. A condition on a key absent from the request context evaluates false, so the statement does not match — harmless for an Allow, but a Deny that never fires. IfExists and the Null operator test presence explicitly.

open as a page

A resource-based policy in AWS grants an AWS service principal such as s3.amazonaws.com or events.amazonaws.com permission to act on your resource. Why is that grant too broad as written, and which condition keys narrow it?

level: seniorimportance: should knowfreq 40%
basics
~20 s

An AWS service principal is the same identity for every customer, so granting it alone lets the service act on your resource on anyone's behalf. Narrow the grant with aws:SourceArn for the specific calling resource and aws:SourceAccount for the account that owns it.

open as a page

In AWS IAM, what is the difference between an implicit deny and an explicit Deny, and what does each mean for how you write and troubleshoot policies?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Every AWS request starts denied. An implicit deny is simply the absence of any matching Allow, and adding an Allow fixes it. An explicit Deny is a statement with Effect Deny, and no Allow anywhere can override it.

open as a page

An API request is made by an IAM role in an account that is part of an AWS Organization, against a resource that has its own resource-based policy. Walk through how AWS decides whether to allow the request when identity policies, that resource policy, an SCP, a permissions boundary and a session policy all apply.

level: middleimportance: must knowfreq 68%
basics
~20 s

AWS gathers every applicable policy, then denies if any of them contains a matching explicit Deny. Otherwise the request must survive each guardrail that applies — SCP, permissions boundary, session policy — and be allowed by an identity-based or resource-based policy; anything else is an implicit deny.

open as a page

A role in account A has an identity policy allowing s3:GetObject on a bucket owned by account B, and the call still returns AccessDenied. What rule governs cross-account access in AWS, and how does it differ from the same-account case?

level: middleimportance: should knowfreq 60%
basics
~20 s

Cross-account access needs an allow on both sides: the caller's identity policy in account A and the resource's own policy in account B. Within a single account the two are a union, so one allow suffices — which is why the same policy works locally and fails across accounts.

open as a page

A principal with the AWS managed AdministratorAccess policy attached still gets AccessDenied on an action. Which parts of AWS IAM evaluation can cause that, and why does attaching another Allow never fix it?

level: seniorimportance: should knowfreq 52%
basics
~20 s

Something is restricting rather than failing to grant: an explicit Deny in any applicable policy, or a guardrail that the action falls outside of — a service control policy, a permissions boundary, or a session policy. All of these subtract from what identity policies grant, so more Allows change nothing.

open as a page

How would you use the IAM policy simulator (the aws iam simulate-principal-policy API) to diagnose an AccessDenied, and what can it not tell you?

level: seniorimportance: nice to knowfreq 38%
basics
~20 s

Point simulate-principal-policy at the caller's ARN with the exact action, resource ARN and any request conditions; the result reports allowed, implicitDeny or explicitDeny plus the statements that matched. It reasons over the policies you give it, not over the live request, so treat an allow as a hypothesis.

open as a page

An AWS IAM role has the AWS managed policy AdministratorAccess attached as its identity policy and also has a permissions boundary that allows only s3:* and cloudwatch:*. What can the role actually do, and what could it do if the boundary were the only policy attached to it?

level: juniorimportance: must knowfreq 45%
basics
~20 s

Effective permissions are the intersection of the two, so the role can call only S3 and CloudWatch actions. A permissions boundary never grants anything, so with the boundary alone and no identity policy the role could do nothing.

open as a page

In AWS, compare a permissions boundary, a service control policy (SCP) and a session policy: what does each attach to, who controls it, and can any of them grant a permission?

level: middleimportance: should knowfreq 52%
basics
~20 s

All three are caps and none grants anything. A permissions boundary attaches to one IAM user or role, an SCP attaches to an organization root, OU or account, and a session policy is passed at AssumeRole time and lives only for that session.

open as a page

An application team wants to create its own IAM roles in an AWS account instead of filing tickets with the platform team, but must never be able to create a role with administrator permissions. How do you delegate iam:CreateRole safely, and what else must the delegation policy lock down?

level: seniorimportance: should knowfreq 38%
basics
~20 s

Grant the IAM write actions only with a StringEquals condition on the iam:PermissionsBoundary key naming your boundary policy, so every role they create carries the cap. Then explicitly deny removing or replacing that boundary, editing the boundary policy itself, and passing roles they should not.

open as a page

Many product teams at your company need self-service on AWS. How would you decide between giving each team its own AWS account governed by organization-level policies and keeping teams together in shared accounts governed by permissions boundaries?

level: principalimportance: nice to knowfreq 26%
basics
~20 s

Separate accounts give hard isolation of blast radius, quotas and billing with guardrails teams cannot lift, at the cost of account sprawl and cross-account plumbing. Permissions boundaries are cheaper and finer-grained but sit inside one account, so they cap identities without isolating resources.

open as a page

In AWS, what is the difference between an IAM user with long-lived access keys and an IAM role assumed through AWS STS, and why do teams prefer the role?

level: juniorimportance: must knowfreq 80%
basics
~20 s

An IAM user's access keys are permanent static secrets belonging to one identity. A role owns no credentials: an allowed principal calls STS AssumeRole and receives a temporary access key, secret and session token that expire on their own.

open as a page

An IAM role carries two separate policy documents: a trust policy and one or more permissions policies. What does each control, and how do you tell from an AccessDenied error which one is at fault?

level: middleimportance: must knowfreq 70%
basics
~20 s

The trust policy is the role's resource policy: it names the principals allowed to call sts:AssumeRole on it. The permissions policies say what the resulting session may do. A denial on sts:AssumeRole points at the trust policy; any later denial points at the permissions policies.

open as a page

What does the `aws sts get-caller-identity` command return, and how do you read the ARN it prints when the caller is using an assumed role?

level: middleimportance: should knowfreq 48%
basics
~20 s

It returns the Account, UserId and Arn that AWS attributes to the credentials just used. For a role session the Arn has the form arn:aws:sts::<account>:assumed-role/<RoleName>/<SessionName>, naming the role and the session rather than any user.

open as a page

A SaaS vendor asks you to create an IAM role in your AWS account that its account can assume, and insists the trust policy pin an sts:ExternalId condition. What attack does that condition prevent, and who is supposed to choose the value?

level: seniorimportance: should knowfreq 38%
basics
~20 s

It stops one of the vendor's other customers from making the vendor use your role on their behalf. The vendor generates a unique ExternalId per customer and passes it on AssumeRole; your trust policy accepts only that value, so a role ARN alone is not enough to be acted on.

open as a page

A long-running batch job assumes an IAM role and then fails with an ExpiredToken error about an hour in, even though the role's MaxSessionDuration is set to 12 hours. What would you check?

level: seniorimportance: nice to knowfreq 32%
basics
~20 s

Check whether the job requested a longer DurationSeconds at all, whether it is role chaining — assuming a second role from the first role's credentials caps the session at one hour — and whether the credentials were captured once into environment variables so nothing can refresh them.

open as a page

An application running on an EC2 instance needs to read objects from an S3 bucket. Explain how it obtains AWS credentials without any access key being stored on the instance, and what an instance profile is as distinct from the IAM role it holds.

level: juniorimportance: must knowfreq 78%
basics
~20 s

Attach an IAM role to the instance through an instance profile — a container object that holds exactly one role. EC2 then publishes temporary credentials for that role on the Instance Metadata Service, and the AWS SDK fetches and refreshes them automatically.

open as a page

An Amazon ECS task definition can reference both a task role and a task execution role. What is each one for, who uses it, and how do the symptoms differ when one of them is missing a permission?

level: middleimportance: must knowfreq 68%
basics
~20 s

The task execution role belongs to the ECS agent and Fargate infrastructure: pulling the image, writing logs, injecting secrets before the container starts. The task role is the application's own identity for AWS API calls at runtime. Missing execution-role permissions fail the start; missing task-role permissions cause AccessDenied inside the app.

open as a page

AWS SDKs resolve credentials through a default provider chain. What sources does it consult, in roughly what order, and why does that ordering explain a container that ignores its attached role and calls AWS as some other principal?

level: middleimportance: should knowfreq 52%
basics
~20 s

The chain walks from most explicit to most ambient: credentials passed in code, then environment variables, then the shared config and credentials files, then container or instance metadata last. Anything left in the environment or a baked profile therefore silently outranks the workload's attached role.

open as a page

A developer with permission to create Lambda functions is told they also need iam:PassRole before they can give a function its execution role. What does iam:PassRole actually authorise, why is it a separate permission, and how would you scope it?

level: seniorimportance: should knowfreq 44%
basics
~20 s

iam:PassRole authorises handing an existing IAM role to an AWS service so that service can assume it. It is separate because creating a resource and choosing its identity are different powers: without it, anyone able to launch compute could attach an admin role and inherit its permissions.

open as a page

Amazon EKS offers two ways to give a pod an IAM role: IAM Roles for Service Accounts (IRSA) and EKS Pod Identity. From the AWS side, how does each wire the pod's Kubernetes ServiceAccount to an IAM role, and what does Pod Identity change operationally?

level: seniorimportance: nice to knowfreq 30%
basics
~20 s

IRSA registers the cluster's OIDC issuer as an IAM identity provider and each role trusts that provider with a condition on the service account subject. Pod Identity instead trusts the pods.eks.amazonaws.com service principal and maps roles through an association, so roles need no per-cluster trust edits.

open as a page

Your team currently gives every engineer an IAM user with long-lived access keys in each of five AWS accounts. What does AWS IAM Identity Center replace that with, and why is it considered safer?

level: juniorimportance: must knowfreq 70%
basics
~20 s

IAM Identity Center centralises workforce sign-in: each engineer exists once in one identity source, is assigned permission sets per account, and receives short-lived credentials at login instead of access keys that live on a laptop forever.

open as a page

In AWS IAM Identity Center, what exactly is a permission set, and what is created inside a member account when you assign one to a group?

level: middleimportance: must knowfreq 62%
basics
~20 s

A permission set is a reusable policy template — managed policies, customer managed policy references, an inline policy, an optional boundary and a session duration. Assigning it provisions an IAM role named AWSReservedSSO_<name>_<suffix> in the target account.

open as a page

A GitHub Actions workflow must deploy to AWS with no access keys stored as repository secrets. How do you set that up with an IAM OIDC identity provider, and which condition must the role's trust policy contain?

level: seniorimportance: should knowfreq 55%
basics
~20 s

Register token.actions.githubusercontent.com as an IAM OIDC identity provider, create a role that trusts it for sts:AssumeRoleWithWebIdentity, and condition the trust policy on both the aud claim and the sub claim so only your repository and branch can assume it.

open as a page

You are connecting an existing corporate identity provider such as Okta or Entra ID to AWS IAM Identity Center for an organization of forty accounts. How do you wire identities in, and how do you make sure someone who leaves loses AWS access?

level: principalimportance: should knowfreq 40%
basics
~20 s

Set the external provider as the identity source: SAML 2.0 carries authentication at sign-in, SCIM 2.0 provisions and deprovisions users and groups. Assign permission sets to synced groups, and keep session durations short because existing sessions survive deprovisioning.

open as a page

How does the AWS CLI obtain credentials for a profile created by `aws configure sso`, and what does running `aws sso login` actually do?

level: middleimportance: nice to knowfreq 45%
basics
~20 s

aws configure sso writes an sso-session block plus a profile naming an account and permission set. aws sso login opens a browser sign-in and caches a short-lived SSO token locally; the CLI exchanges that token for temporary role credentials per command.

open as a page

Signing in to an Amazon Cognito user pool returns three tokens. Name them, and say which one your own backend API should accept as proof that the caller is authorized.

level: juniorimportance: must knowfreq 70%
basics
~20 s

A Cognito user pool sign-in returns an ID token, an access token and a refresh token. Your API should accept the access token, which carries scopes and group claims; the ID token describes the user to the client, and the refresh token only obtains new tokens.

open as a page

In Amazon Cognito, what is the difference between a user pool and an identity pool, and what does each one hand back to the client at the end of a successful sign-in?

level: middleimportance: must knowfreq 82%
basics
~20 s

A Cognito user pool is the user directory: it authenticates people and returns JWTs. An identity pool is a credential broker: it takes a token you already have and exchanges it for temporary AWS credentials tied to an IAM role. Many apps use both, and some use only one.

open as a page

Your service verifies Amazon Cognito user pool JWTs itself against the pool's published JWKS. Beyond checking the signature and expiry, which Cognito-specific claims must you check, and what does offline verification fail to notice?

level: seniorimportance: should knowfreq 48%
basics
~20 s

Check that iss names your pool, that token_use matches the token type you expect, and that the audience claim — aud on an ID token, client_id on an access token — is your app client. Offline verification cannot see revocation, disabled users or changed groups until the token expires.

open as a page

For a mobile app that uploads photos to Amazon S3, you can hand the device temporary AWS credentials from a Cognito identity pool, or route uploads through your own API. How do you decide, and what must the identity pool's IAM role policy do if you hand out credentials?

level: principalimportance: should knowfreq 38%
basics
~20 s

Decide on how much you need to enforce per request. Identity pool credentials remove a hop and scale for free, but every rule must be expressible in an IAM policy — so the role must confine each user to their own key prefix using the identity's subject as a policy variable. Anything beyond that argues for your own API.

open as a page

A user who registered in your Amazon Cognito user pool with email and password later signs in with "Continue with Google" and lands in an empty account with none of their data. Explain what Cognito did and how you would fix it.

level: seniorimportance: nice to knowfreq 32%
basics
~20 s

Cognito created a second, separate user in the pool for the Google identity, with its own sub, so your application saw a new customer. Fix it by linking the federated identity to the existing native user with the AdminLinkProviderForUser API, and only after proving the two really are the same person.

open as a page

In AWS Organizations, what is the difference between the management account and a member account, and what does grouping accounts into organizational units (OUs) give you?

level: juniorimportance: must knowfreq 60%
basics
~20 s

In AWS Organizations one management account creates the organization, pays every bill and cannot be restricted by service control policies; the rest are member accounts holding workloads. OUs group accounts so one attached policy applies to all beneath.

open as a page

You attach a service control policy that allows `s3:*` to an OU in AWS Organizations, but principals in those accounts still cannot call Amazon S3. Why did nothing change, and what does an SCP actually do?

level: middleimportance: must knowfreq 72%
basics
~20 s

A service control policy only sets a ceiling on what an account may be allowed to do; it never grants anything. Allowing s3:* merely leaves S3 inside the ceiling — some IAM policy still has to actually grant the S3 permission.

open as a page

Service control policies in AWS Organizations can be run as a deny list or as an allow list. Compare the two strategies, and say what the allow-list approach costs you operationally.

level: seniorimportance: should knowfreq 48%
basics
~20 s

A deny list keeps the default FullAWSAccess policy and adds targeted Deny statements for a few forbidden things. An allow list detaches FullAWSAccess and enumerates every permitted service — tighter, but it blocks any service nobody remembered to list.

open as a page

An SCP attached to your AWS organization root denies `s3:DeleteBucket`, yet an administrator in the management account deletes a bucket successfully. Why, and what does that imply for how the management account should be used?

level: seniorimportance: should knowfreq 38%
basics
~20 s

Service control policies never restrict principals in the management account, no matter where the policy is attached. Because the organization's own guardrails do not apply there, the management account should hold no workloads and very few principals.

open as a page

A company runs everything in a single AWS account and asks you to move to a multi-account setup. How would you structure the accounts and OUs, and what does AWS Control Tower add over assembling it yourself?

level: principalimportance: should knowfreq 44%
basics
~20 s

Split by blast radius and governance rather than by team: an empty management account, a Security OU with log archive and audit accounts, shared infrastructure, and separate production and non-production workload accounts under OUs that carry the guardrail SCPs. Control Tower assembles and maintains that baseline for you.

open as a page

AWS KMS caps the plaintext of a single symmetric Encrypt call at a few kilobytes. Walk through how you encrypt a 500 MB file under a KMS key instead: which API you call, what it returns, and what you store next to the ciphertext.

level: middleimportance: must knowfreq 75%
basics
~20 s

Call kms:GenerateDataKey. KMS returns one data key twice, as plaintext and encrypted under your KMS key. Encrypt the file locally with the plaintext copy, wipe it from memory, and store the encrypted copy beside the ciphertext.

open as a page

A role in the same AWS account has an IAM policy allowing kms:Decrypt on a customer managed KMS key, but its calls still fail with AccessDenied. Why does KMS behave differently from most AWS resource policies here, and how do you fix it?

level: seniorimportance: must knowfreq 58%
basics
~20 s

Every KMS key has a mandatory key policy, and it is the root of authority for that key. An IAM policy grants nothing unless the key policy also allows the principal, either directly or through its default statement that delegates to IAM.

open as a page

In AWS KMS, what is the practical difference between an AWS owned key, an AWS managed key, and a customer managed key?

level: juniorimportance: should knowfreq 62%
basics
~20 s

They differ in who controls the key policy. AWS owned keys are invisible and shared across customers. AWS managed keys appear in your account under aws/ aliases but their policy is fixed. Only customer managed keys let you set policy, rotation and deletion.

open as a page

You enable automatic key rotation on a customer managed symmetric AWS KMS key. What actually changes, what happens to data already encrypted under it, and when would you instead create a new key and repoint an alias?

level: middleimportance: should knowfreq 48%
basics
~20 s

KMS generates new backing key material and uses it for new encrypt operations. The key ID, ARN and alias are unchanged, old backing keys are retained so existing ciphertext still decrypts, and nothing is re-encrypted. Manual rotation means a new key plus an alias repoint.

open as a page

For a multi-tenant platform on AWS, how would you decide KMS key granularity — one key for the account, one per service, or one per tenant — and what forces the answer?

level: principalimportance: should knowfreq 32%
basics
~20 s

Granularity follows the blast radius and erasure requirements, then is checked against cost and quota. Per-tenant keys buy isolation and cryptographic erasure; a shared key with per-tenant encryption context and grants buys the same authorization boundary far more cheaply.

open as a page

AWS services such as S3, EBS, RDS and DynamoDB all advertise encryption at rest. Concretely, which threats does server-side encryption at rest remove, and which ones does it leave completely untouched?

level: middleimportance: must knowfreq 66%
basics
~20 s

AWS at-rest encryption protects bytes on the storage media — decommissioned drives and raw copies taken outside the service API. It stops nothing at the API layer: the service decrypts transparently for any caller whose IAM and key permissions allow the read.

open as a page

AWS endpoints such as S3 accept requests over both HTTP and HTTPS. How do you make TLS a hard requirement for a bucket rather than a convention, and what exactly does the control you use evaluate?

level: middleimportance: should knowfreq 41%
basics
~20 s

Attach a resource policy statement that denies every action when the global condition key aws:SecureTransport is false. It is a boolean AWS sets per request, true only when the request reached the AWS endpoint over TLS, so the deny turns plain-HTTP access into an error rather than a lapse.

open as a page

A role in account B is allowed s3:GetObject by both its own IAM policy and the bucket policy in account A, yet every download returns AccessDenied. The objects are encrypted with a customer managed AWS KMS key owned by account A. Why does the request still fail, and what has to change?

level: seniorimportance: should knowfreq 47%
basics
~20 s

Reading KMS-encrypted data needs a second authorization — kms:Decrypt on the key — and a KMS key policy is evaluated independently of S3's policies. Account A's key policy does not name the role in account B, so the decrypt is denied and S3 surfaces AccessDenied.

open as a page

A compliance requirement states that a dataset must be encrypted with "keys we control". In AWS terms, what concretely changes when you move that data from an AWS managed KMS key to a customer managed key, and what does that choice cost you?

level: seniorimportance: should knowfreq 43%
basics
~20 s

A customer managed key gives you an editable key policy, so you can grant, condition and revoke use independently of the service's own permissions, share with other accounts, and audit every use. The cost is a monthly key charge, per-request charges, and a hard availability dependency on that policy staying correct.

open as a page

You need to be able to state that every EBS volume, S3 object and RDS database created across a 200-account AWS organization is encrypted at rest. How do you get from "mostly encrypted" to a defensible guarantee, and what does each control you add actually buy?

level: principalimportance: nice to knowfreq 30%
basics
~20 s

Stack three layers: service defaults so the encrypted path is the easy one, preventive organization policies that deny creation when an encryption condition key is false, and detective scanning for the gaps and the backlog. Only the preventive layer, which binds account admins too, supports a guarantee.

open as a page

Your service on AWS needs one database password plus about forty non-secret configuration values. Would you put them in AWS Secrets Manager or in SSM Parameter Store, and what concretely drives that decision?

level: middleimportance: must knowfreq 76%
basics
~20 s

Secrets Manager buys managed rotation, a resource policy on the secret for cross-account reads, and cross-Region replication, and charges per secret per month. SSM Parameter Store is free at standard tier and fits plain config, with SecureString when a value must be encrypted.

open as a page

In AWS SSM Parameter Store, what does storing a value as a SecureString change compared with a String parameter, and what does a caller need in order to get the plaintext back?

level: juniorimportance: should knowfreq 58%
basics
~20 s

A SecureString parameter is encrypted with a KMS key instead of being stored in the clear. Reading the plaintext needs two things: the GetParameter call must ask for decryption via WithDecryption, and the caller's IAM policy must allow kms:Decrypt on the key as well as ssm:GetParameter.

open as a page

A Lambda function calls GetSecretValue against AWS Secrets Manager at the top of every invocation. What goes wrong as traffic grows, and how do you fix it without pinning a stale credential forever?

level: seniorimportance: should knowfreq 40%
basics
~20 s

Every invocation pays a network round trip and a KMS decrypt, the API calls are billed per request, and at high concurrency the account starts getting throttled. Cache the value per execution environment with a bounded lifetime, and refetch on an authentication failure so rotation still lands.

open as a page

Explain how rotation works in AWS Secrets Manager: what the AWSCURRENT, AWSPENDING and AWSPREVIOUS staging labels are for, and what the rotation function is expected to do at each of its four steps.

level: seniorimportance: should knowfreq 48%
basics
~20 s

Secrets Manager versions a secret and moves staging labels between versions. AWSCURRENT is what readers get by default, AWSPENDING is the candidate being rotated in, AWSPREVIOUS is the last good one. The rotation function runs createSecret, setSecret, testSecret and finishSecret.

open as a page

In an ECS task definition, what is the difference between putting a value in a container's `environment` list and its `secrets` list, and what happens to an already-running task when the referenced secret is rotated?

level: middleimportance: nice to knowfreq 34%
basics
~20 s

An environment entry stores the literal value in the task definition, visible to anyone who can describe it. A secrets entry stores only an ARN, and the agent resolves it at task start using the task execution role. Rotation does not reach running tasks; they keep the value injected at launch.

open as a page

Your team enabled AWS CloudTrail on day one. After a suspected data exfiltration you can see who changed an S3 bucket policy, but you cannot find which objects were downloaded. Why, and what would have made those reads visible?

level: middleimportance: must knowfreq 70%
basics
~20 s

CloudTrail records management events (control-plane calls such as PutBucketPolicy) by default, but data events — S3 object-level GetObject and PutObject, Lambda Invoke, DynamoDB item operations — are off unless you explicitly enable them, and they are billed per event.

open as a page

In AWS IAM, what is the credential report, and how would you use it to answer "which IAM users still hold stale long-lived credentials, and is MFA enabled on the root user?"

level: juniorimportance: should knowfreq 40%
basics
~10 s

The IAM credential report is an account-wide CSV listing every IAM user and the root user, with password state, access-key rotation and last-used dates, and MFA status. One download answers stale-credential and root-MFA questions.

open as a page

You inherit an IAM role whose attached policy grants wildcard actions, and you are asked to cut it back to least privilege without breaking the workload. Which AWS evidence sources tell you what the role actually used, and what are their blind spots?

level: seniorimportance: should knowfreq 50%
basics
~20 s

Use three evidence sources: IAM service last-accessed data (Access Advisor) for which services the role touched and when, IAM Access Analyzer to generate a policy from CloudTrail history and to flag unused access, and the CloudTrail record itself for individual calls.

open as a page

You run an AWS Organization with dozens of member accounts. Design CloudTrail so that an attacker who obtains administrator access inside one member account cannot erase the record of what they did there.

level: principalimportance: should knowfreq 38%
basics
~20 s

Create a multi-region organization trail from the management or delegated administrator account: member accounts cannot stop or delete it. Deliver to an S3 bucket in a separate log-archive account whose write path the workload administrators do not control, with integrity validation on.

open as a page

An auditor asks you to prove that the AWS CloudTrail logs you handed over have not been altered and that no entries were removed. What does CloudTrail's log file integrity validation give you, and what does it not prove?

level: middleimportance: nice to knowfreq 28%
basics
~20 s

With log file integrity validation on, CloudTrail delivers hourly digest files that hash each delivered log file and chain to the previous digest, signed by AWS. Validation detects modified, deleted or inserted files — it does not prove every API call was logged.

open as a page

In AWS, which detection service would you reach for to spot an active attack, to catch drift from a security baseline, to find known CVEs in running workloads, and to locate personal data sitting in S3 — and what does Security Hub add on top of them?

level: juniorimportance: must knowfreq 70%
basics
~20 s

GuardDuty detects active threats from AWS logs, AWS Config records resource state and flags drift from rules, Amazon Inspector scans workloads for known CVEs, and Macie finds sensitive data in S3. Security Hub aggregates all of their findings.

open as a page

What data does Amazon GuardDuty analyse to produce its findings, and why does enabling it not require you to first turn on VPC Flow Logs or CloudTrail S3 data events yourself?

level: middleimportance: must knowfreq 60%
basics
~20 s

GuardDuty reads AWS-side telemetry directly from the service plane: CloudTrail management and S3 data events, VPC Flow Logs, and Route 53 Resolver DNS query logs. It gets its own independent copy, so you neither enable nor pay for those logs.

open as a page

In AWS Config, how does a rule actually detect that a resource has drifted from your baseline, and how would you make that drift correct itself?

level: middleimportance: should knowfreq 50%
basics
~20 s

AWS Config records a configuration item whenever a resource changes, then evaluates rules against it — triggered by the change or on a schedule — marking resources COMPLIANT or NON_COMPLIANT. Attaching a remediation action runs an SSM Automation runbook to fix them.

open as a page

How does AWS Security Hub aggregate findings across a multi-account, multi-Region AWS Organization, and what has to be enabled before its standards controls evaluate anything?

level: seniorimportance: should knowfreq 44%
basics
~20 s

Security Hub uses an Organizations delegated administrator with member accounts auto-enabled, plus a designated aggregation Region that collects findings from linked Regions. Its standards controls are largely evaluated through AWS Config, so Config recording must be on.

open as a page

You are switching on AWS detection and compliance services across a 200-account AWS Organization. How do you decide what to enable where, and what keeps the bill and the finding volume from becoming unmanageable?

level: principalimportance: should knowfreq 36%
basics
~20 s

Enable through Organizations with a delegated security account and auto-enable for new accounts, cover every allowed Region, and treat AWS Config's recorder scope and Macie's scan targets as the main cost dials. Suppress known exceptions at ingestion, not by ignoring dashboards.

open as a page

In AWS IAM, what are users, groups and roles, and why do production AWS accounts prefer roles over IAM users holding long-lived access keys?

level: juniorimportance: must knowfreq 68%
basics
~20 s

AWS IAM users are identities with long-lived credentials, groups are policy-carrying containers of users, and roles are identities that anything trusted can take on to get expiring credentials. Roles are preferred because nothing permanent is left lying around to leak.

open as a page