8 of 8 cards free · no sign-in needed
A user is a persistent identity with long-term credentials for a person/app. A role provides temporary credentials that are assumed by users, services, or apps — preferred for workloads.
A collection of users; attach policies to the group and all members inherit them. The scalable way to manage permissions.
A principal calls AssumeRole (via STS) and receives temporary security credentials scoped to the role's permissions — no long-term keys stored on the resource.
Identity-based policies attach to users/groups/roles. Resource-based policies attach to a resource (e.g. an S3 bucket policy) and specify who may access it.
By default everything is denied. An explicit Allow grants access; an explicit Deny always overrides any Allow. No matching Allow = implicit deny.
A JSON document with Effect (Allow/Deny), Action, Resource, and optional Condition. Conditions enable fine-grained, context-aware control.
Grant only the permissions required to perform a task. Start minimal and add as needed — a core Security-pillar best practice.
Sign in (free) to flip every card, mark what you know, and pick up exactly where you left off.
After sign-in: Space flip · ←→ navigate · K knew it · S skip