Soru

Zorluk: KolayIdentity and Access Management (IAM)

A business analyst needs temporary access to run a weekly report on billing data in the AWS Management Console. To follow the principle of least privilege and avoid managing long-term credentials, which approach should the administrator use?

  1. A
    Create a dedicated IAM user and generate permanent access keys for the analyst to use weekly.
  2. B
    Provide the analyst with the login credentials for the AWS account root user for their weekly tasks.
  3. Configure an IAM role with the necessary billing permissions for the analyst to assume temporarily.Cevap
  4. D
    Request AWS Support to generate and deliver the billing report under the AWS shared responsibility model.

Cevap

Configure an IAM role with the necessary billing permissions for the analyst to assume temporarily.
Configuring an IAM role is the correct approach because roles provide temporary security credentials and do not require sharing or managing long-term access keys.

Adım Adım Çözüm

1
Identify the access requirement, which is temporary and should not rely on long-term credentials.
This eliminates options that require creating permanent IAM user credentials or sharing root account credentials.
Minimizing long-term credentials reduces the risk of credential exposure.
2
Select the AWS IAM entity designed to grant temporary permissions.
An IAM role is chosen as it provides temporary credentials that expire automatically.
IAM roles allow users or services to assume specific permissions for a limited duration without needing long-term access keys.

Anahtar Kavram

AWS IAM Roles and Temporary Credentials
Tahmini Süre:45s
Bu soruyu puanla