Soru

Zorluk: OrtaIdentity and Access Management (IAM)

A growing digital marketing agency wants to streamline permissions management for its designers, copywriters, and analysts. The agency needs to ensure that when a new designer joins, they automatically receive the correct permissions, and when they change roles, their permissions are updated easily. Which of the following options represent AWS-recommended best practices to achieve this? (Select TWO.)

  1. Organize IAM users into IAM groups based on job functions and attach policies to the groups.Cevap
  2. B
    Attach individual IAM policies directly to each employee's IAM user account.
  3. Apply the principle of least privilege by granting only the permissions required for each job function.Cevap
  4. D
    Create a single shared IAM user account with administrative privileges for all members of the design team.
  5. E
    Use the AWS account root user credentials to perform daily management of employee permissions.

Cevap

Organizing IAM users into groups based on job functions and applying the principle of least privilege by granting only the necessary permissions.
Organizing users into IAM groups based on job functions simplifies the management of permissions because policies can be attached to the group rather than individual users. Moving a user between groups automatically updates their permissions. Additionally, applying the principle of least privilege ensures that users have only the minimum access necessary, which improves security.

Adım Adım Çözüm

1
Analyze the requirements for streamlining access control and permissions updates for different job functions.
Identify that managing permissions individually is inefficient and that groups are the AWS-recommended way to manage permissions for multiple users with similar job functions.
Grouping simplifies policy attachment and ensures consistency.
2
Evaluate the security principles for granting access to resources.
Apply the principle of least privilege, ensuring that users have only the permissions required for their specific role.
This reduces the blast radius of compromised credentials.

Anahtar Kavram

AWS IAM Groups and the Principle of Least Privilege
Bu soruyu puanla