Identity and Access Management

Domain 4: Identity and Access Management

25 practice questions for Domain 4 of the AWS Certified Security - Specialty (SCS-C03) exam, which makes up 20% of its scored content. Your answers count towards one score and one timer for the whole exam.

Domain 4: Identity and Access Management

20% of scored content · 25 practice questions

115. A permission set in AWS IAM Identity Center must allow a four-hour analyst session, but sessions are ending after one hour. Which cause should the team investigate first?

Answer and explanation

Answer: A. A permission set provisions an IAM role in each account, and the effective session length is bounded by that role's maximum session duration as well as the permission set's own setting. The identity source governs authentication rather than session length. Assignment through a group or directly to a user does not change duration. Identity Center is a global service and Region alignment does not affect sessions.

116. Servers authenticating through IAM Roles Anywhere have begun failing to obtain credentials, although their certificates have not expired. Which cause should the team investigate first?

Answer and explanation

Answer: A. Roles Anywhere validates the presented certificate against the trust anchor's chain and revocation state on each request, so a chain or revocation list change breaks authentication even when the leaf certificate remains valid. Clock drift affects signature validation more broadly and would usually produce a different error. Session duration governs the credentials once issued. The trust policy must name the Roles Anywhere service principal rather than the account.

117. An organization must require multi-factor authentication for every workforce user without managing a separate factor for each account. Which solution meets these requirements?

Answer and explanation

Answer: B. Enforcing the factor at the identity provider means one enrolment covers every account the user federates into. Root user protection is essential but does not cover workforce access. Per-role conditions work but must be applied to every role in every account. A service control policy can require the condition but still depends on each account's authentication path rather than centralising enrolment.

118. Several IAM mechanisms must be matched to the control each one provides. (Match each mechanism to its control.)

  1. Service control policy
  2. Permissions boundary
  3. Session policy
  4. Resource control policy
Answer and explanation

Answer: 1-B, 2-A, 3-C, 4-D. Service control policies bound principals in an account, while resource control policies bound access to resources, and the two are complementary rather than interchangeable. A permissions boundary limits one identity and is the mechanism that makes safe delegation of role creation possible. A session policy applies only to the credentials issued in one AssumeRole call. All four restrict rather than grant, which is why none of them can be used to give an identity a permission it does not already have.

119. A developer role must be prevented from creating IAM roles more privileged than itself. Which solution meets these requirements?

Answer and explanation

Answer: C. A permissions boundary caps the effective permissions of any role created, and conditioning role creation on attaching that boundary closes the escalation path. Granting iam:* is precisely the escalation being prevented. A permissive service control policy removes the guardrail. A written standard is not an enforced control.

120. A resource policy must grant access to any principal in the organization and remain correct as accounts join and leave. Which solution meets these requirements?

Answer and explanation

Answer: A. aws:PrincipalOrgID matches any principal in the specified organization, so the policy needs no change as membership varies. A list of account identifiers must be maintained. A VPC list restricts by network origin and requires similar maintenance. A principal ARN wildcard does not express organization membership and would match roles in accounts outside it.

121. An organization must prevent its resources from being accessed by identities outside the organization, regardless of the resource policies attached to them. Which solution meets these requirements?

Answer and explanation

Answer: C. Resource control policies set a maximum permission ceiling on resources in the organization, complementing service control policies which bound principals. A service control policy restricts what identities in the account may do rather than who may reach its resources. A permissions boundary limits an individual identity. A Config rule reports after the fact.

122. An application must externalize fine-grained end-user authorization rather than embedding permission logic in its code. Which solution meets these requirements?

Answer and explanation

Answer: C. Verified Permissions is a managed policy engine for application-level authorization, so policies live outside the code and are evaluated per request. IAM policies govern what the application may call in AWS rather than what its end users may do. A configuration file and a table both require the application to implement evaluation itself.

123. A security team must identify IAM roles and permissions that have not been used for 90 days so they can be removed. Which solution meets these requirements?

Answer and explanation

Answer: A. Access Analyzer offers two distinct analyser types, and unused access analysis is the one that reports roles, permissions, and credentials that have gone unused for a configured period. External access analysis reports access granted outside the zone of trust, which is a different question. A credential report covers users rather than roles and their granted permissions. Querying CloudTrail is possible but requires building the analysis and misses permissions never exercised.

124. A federated user's session must be limited to one hour although the identity provider requests four. Which control determines the outcome?

Answer and explanation

Answer: B. The role's maximum session duration bounds what can be issued, so a longer request is reduced to it. The provider's request is a ceiling rather than a guarantee. A permission set provisions the role, so its setting is bounded by the same limit. There is no account-wide default that overrides the role.

125. An IAM Roles Anywhere trust anchor must be restricted so only certificates with a specific attribute may assume a role. Which approach is appropriate?

Answer and explanation

Answer: C. Roles Anywhere surfaces certificate attributes as condition keys the trust policy can match, which enforces the restriction at credential issuance. Constraining the authority's issuance is useful but does not enforce it at assumption. A trust anchor per value multiplies configuration. Application-side filtering is not an enforced control.

126. Multi-factor authentication must be required for a specific sensitive action but not for routine access. Which approach is appropriate?

Answer and explanation

Answer: B. A condition scoped to the sensitive action's statement requires the factor only where it matters. Requiring it for all access is broader than the requirement. A separate role without a condition does not require the factor. A password policy governs password properties rather than action-level conditions.

127. An explicit deny in a service control policy and an explicit allow in an identity policy apply to the same action. Which is the outcome?

Answer and explanation

Answer: A. An explicit deny in any applicable policy is final regardless of allows elsewhere. Identity policies are not evaluated after service control policies in a way that overturns a deny. A service control policy sets a ceiling and an explicit deny within it is binding. Attachment order is irrelevant.

128. A resource policy grants access to an external account, and a resource control policy at the organization root restricts access to organization principals. Which is the outcome?

Answer and explanation

Answer: D. A resource control policy sets a maximum on access to resources in the organization, and a resource policy cannot exceed it. Specificity does not override a ceiling. Resource control policies bound access to resources rather than the identities making requests. The external account's organization membership does not change the ceiling.

129. A permissions boundary permits an action that the identity policy does not grant. Which is the outcome?

Answer and explanation

Answer: B. A boundary caps permissions rather than granting them, so an action must be permitted by both the boundary and the identity policy. A boundary alone grants nothing. Precedence does not apply to a mechanism that only restricts. A resource policy can permit cross-account access but does not overcome an absent identity grant within the same account.

130. An IAM Access Analyzer external access finding names a role trusted by a third-party account that is a legitimate vendor. Which action is appropriate?

Answer and explanation

Answer: D. An archive rule suppresses known-acceptable findings while leaving detection of new external access intact. Deleting a finding does not prevent it recurring. Disabling analysis for a resource type loses coverage. The zone of trust is the organization and is not extended to third parties.

131. A developer must be able to pass a role to a service but not to any role more privileged than intended. Which approach is appropriate?

Answer and explanation

Answer: A. Scoping PassRole to named role ARNs permits exactly the intended delegation. Granting it on all roles permits escalation to any role. Denying it entirely creates a bottleneck. Granting role creation without a boundary is a broader escalation path.

132. An organization must prevent the creation of long-term IAM access keys. Which approach is appropriate?

Answer and explanation

Answer: B. A service control policy denying the action prevents creation. Deletion after discovery leaves a window. A Config rule reports. Multi-factor authentication permits creation by an authenticated user.

133. IAM Identity Center users must re-authenticate after a defined period regardless of activity. Which configuration is appropriate?

Answer and explanation

Answer: A. Both the permission set duration and the Identity Center session settings govern how long access persists. Role duration alone bounds the credential rather than the portal session. Multi-factor authentication strengthens sign-in without bounding duration. Manual reassignment is not a session control.

134. A third party must access a customer's account, and the customer must be protected against the confused deputy problem. Which configuration is required?

Answer and explanation

Answer: B. An external ID prevents another of the third party's customers being used to assume the role. Source IP, multi-factor authentication, and session duration all constrain access without addressing the confused deputy specifically.

135. An organization must prevent member accounts from disabling security services regardless of local permissions. Which approach is appropriate?

Answer and explanation

Answer: B. A service control policy caps permissions and cannot be removed from inside the account. Removing administrator access is broad and reversible by root. Re-enabling and alerting both act after the service has been disabled.

136. A role's permissions must be reduced to what it has actually used over the past three months. Which source informs this?

Answer and explanation

Answer: C. Unused access findings and service last accessed data show what has been exercised. Policy documents show what is granted. Creation date and assumption breadth do not indicate usage.

137. A resource policy must permit access only from a specific VPC endpoint regardless of the caller's identity. Which condition is appropriate?

Answer and explanation

Answer: B. aws:sourceVpce restricts to requests arriving through a named endpoint. Organization ID, source IP, and principal ARN all restrict by caller or network origin rather than endpoint.

138. An organization must prevent a resource policy in any account from granting access to an unknown external account. Which approach is appropriate?

Answer and explanation

Answer: C. A resource control policy caps who may reach organization resources irrespective of resource policies. Denying policy modification blocks legitimate changes. Quarterly review is retrospective. Access Analyzer reports rather than prevents.

139. A team must be able to create roles but not attach policies granting privilege escalation. Which approach is appropriate?

Answer and explanation

Answer: B. A required boundary caps any created role's effective permissions. Full access with review permits escalation between reviews. Denying IAM entirely blocks legitimate work. A fixed role set cannot fit every workload.