Soru

Zorluk: KolayIdentity and Access Management (IAM)

A newly hired cloud administrator needs to perform daily operational tasks in the AWS Management Console, such as configuring network settings and managing Amazon S3 buckets. Which AWS security best practice should be followed to grant these permissions?

  1. Create an individual IAM user with the necessary permissions for the administrator's daily tasks.Cevap
  2. B
    Provide the administrator with the AWS account root user login credentials.
  3. C
    Use an IAM role for the administrator's persistent daily console login instead of a user account.
  4. D
    Submit a request to AWS Support to configure the network and S3 buckets on the customer's behalf.

Cevap

Create an individual IAM user with the necessary permissions for the administrator's daily tasks.
Creating an individual IAM user for daily tasks aligns with the AWS best practice of maintaining separate identities for auditing and applying the principle of least privilege, while avoiding the use of the root user.

Adım Adım Çözüm

1
Analyze the operational requirements.
A new internal administrator needs persistent access to the AWS Management Console to perform everyday administrative tasks such as configuring networks and S3.
Understanding the identity type and access frequency helps determine the correct IAM entity to use.
2
Apply AWS security best practices for identity management.
The AWS account root user should not be used for daily tasks. Instead, an individual IAM user should be created with standard administrator permissions mapped to their specific identity.
This establishes individual accountability, supports the principle of least privilege, and protects the root account.

Anahtar Kavram

AWS IAM Best Practices - Avoiding Root User and Using Individual IAM Users
Tahmini Süre:45s
Bu soruyu puanla