Soru

Zorluk: ZorIdentity and Access Management (IAM)

A technology company wants to delegate administrative capabilities by allowing department leads to create and manage IAM roles for their developers. To maintain strict security, the central security team must ensure that these department leads cannot grant permissions that exceed a predefined set of allowed services, even if they create policies with administrator access. Which AWS Identity and Access Management (IAM) feature should the security team implement to enforce this maximum permission limit?

  1. A
    Service Control Policies (SCPs)
  2. Permissions boundariesCevap
  3. C
    IAM groups with inline policies
  4. D
    AWS account root user credentials

Cevap

Permissions boundaries
Permissions boundaries are specifically designed to set the maximum permissions that an identity-based policy can grant to an IAM entity. This allows senior administrators to delegate the creation of IAM roles to department leads, while ensuring that the leads cannot create roles with permissions that exceed the boundary.

Adım Adım Çözüm

1
Analyze the requirement to delegate IAM role management while preventing permission escalation.
Identify that the department leads need to create IAM roles, but must be restricted from granting administrative access to those roles.
This establishes the need for a mechanism that defines the maximum possible permissions that can be delegated.
2
Compare the capabilities of IAM features designed to limit maximum permissions.
Determine that permissions boundaries specifically set the maximum permissions that an identity-based policy can grant to an IAM entity (user or role) within an account.
This aligns with the security best practice of delegation with boundaries.

Anahtar Kavram

Permissions boundaries are used to restrict the maximum permissions that an identity-based policy can grant to an IAM user or role.
Tahmini Süre:2m 0s
Bu soruyu puanla