Soru

Zorluk: OrtaIdentity and Access Management (IAM)

A company's security team needs to define a custom set of permissions for their database administrators. The policy must be reusable across multiple IAM groups, support version history, and allow for easy rollbacks if a change causes issues. Which type of IAM policy should the security team implement to meet these requirements?

  1. Customer managed policyCevap
  2. B
    Inline policy
  3. C
    AWS managed policy
  4. D
    Root user policy

Cevap

Customer managed policy
Customer managed policies are standalone policies created and managed by the customer. They can be attached to multiple IAM groups, support up to five versions for rollback capability, and allow full customization of permissions.

Adım Adım Çözüm

1
Analyze the requirements for the custom policy: it must be reusable across multiple groups, support version control, and allow rollbacks.
Identified that the policy must be a standalone resource managed by the customer, rather than an inline policy or a policy controlled by AWS.
Standalone policies permit reuse, and customer-created policies allow custom configurations and versions.
2
Evaluate policy options against these requirements: customer managed policies offer version history and multi-entity attachment.
Confirmed that customer managed policies fit all requirements perfectly, whereas inline policies lack reuse and AWS managed policies lack customization/version control.
To choose the correct best practice for managing customized permission sets at scale.

Anahtar Kavram

AWS IAM Policy Types
Tahmini Süre:1m 0s
Bu soruyu puanla