Flashcards / Architecting: Account Security
← Decks

Architecting: Account Security

8 of 8 cards free · no sign-in needed

CONCEPT
AWS account root user

Click to reveal answer

ANSWER
The identity created with the account; has full access to everything. Lock it down: enable MFA, do not use it for daily tasks, and create IAM identities instead.

Click to flip back

  1. IAM users vs roles

    A user is a persistent identity with long-term credentials for a person/app. A role provides temporary credentials that are assumed by users, services, or apps — preferred for workloads.

  2. IAM user groups

    A collection of users; attach policies to the group and all members inherit them. The scalable way to manage permissions.

  3. Assuming a role

    A principal calls AssumeRole (via STS) and receives temporary security credentials scoped to the role's permissions — no long-term keys stored on the resource.

  4. Identity-based vs resource-based policies

    Identity-based policies attach to users/groups/roles. Resource-based policies attach to a resource (e.g. an S3 bucket policy) and specify who may access it.

  5. How IAM evaluates policies

    By default everything is denied. An explicit Allow grants access; an explicit Deny always overrides any Allow. No matching Allow = implicit deny.

  6. IAM policy elements

    A JSON document with Effect (Allow/Deny), Action, Resource, and optional Condition. Conditions enable fine-grained, context-aware control.

  7. Least privilege

    Grant only the permissions required to perform a task. Start minimal and add as needed — a core Security-pillar best practice.

🔒

Track what you know

Sign in (free) to flip every card, mark what you know, and pick up exactly where you left off.

Sign in to continueCreate free account

After sign-in: Space flip · ←→ navigate · K knew it · S skip

Other decks you might like

☁️
AWS Practitioner Essentials
10 cards
💰
Cloud Pricing & Billing
15 cards
📋
CLF-C02 Exam Domains
18 cards
cloud
CLF-C02: Introduction to AWS
6 cards