Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 24 pages
Exam (elaborations)

AWS IAM Fundamentals for Cloud Practitioner: Users, Groups, Policies, and Security Complete Exam Study Questions with Verified Answers

Document preview thumbnail
Preview 3 out of 24 pages

AWS IAM Fundamentals for Cloud Practitioner: Users, Groups, Policies, and Security Complete Exam Study Questions with Verified Answers 1. What does IAM stand for? - ANSWER Identity and Access Management 2. What is AWS IAM? - ANSWER A service used to securely control access to AWS resources. 3. What are the three main IAM components? - ANSWER Users, Groups, Roles. 4. Should the root account be used for daily administrative tasks? - ANSWER No. Use it only for specific account-level tasks and protect it with MFA. 5. Which of the following are benefits of using Amazon EC2 roles? (Choose 2 answers) a. No policies are required. b. Credentials do not need to be stored on the Amazon EC2 instance. c. Key rotation is not necessary. d. Integration with Active Directory is automatic. - ANSWER B, C. Amazon EC2 roles must still be assigned a policy. Integration with Active Directory involves integration between Active Directory and IAM via SAML. 6. Which of the following are based on temporary security tokens? (Choose 2 answers) a. Amazon EC2 roles b. MFA c. Root user d. Federation - ANSWER A, D. Amazon EC2 roles provide a temporary token to applications running on the instance; federation maps policies to identities from other sources via temporary tokens. 7. Your security team is very concerned about the vulnerability of the IAM administrator user accounts (the accounts used to configure all IAM features and accounts). What steps can be taken to lock down these accounts? (Choose 3 answers) a. Add multi-factor authentication (MFA) to the accounts. b. Limit logins to a particular U.S. state. c. Implement a password policy on the AWS account. d. Apply a source IP address condition to the policy that only grants permissions when the user is on the corporate network. e. Add a CAPTCHA test to the accounts. - ANSWER A, C, D 8. What is the format of an IAM policy? - ANSWER JSON 9. Who has full access to all AWS services and resources by default? - ANSWER The AWS account root user. 10. What is an IAM User? - ANSWER A permanent identity used by a person or application with long-term credentials. 11. What is an IAM Group? - ANSWER A collection of IAM users that share the same permissions. 12. Can IAM Groups contain other IAM Groups? - ANSWER No. IAM Groups can contain users but not other groups. 13. What is an IAM Policy? - ANSWER A JSON document that defines allowed or denied actions on AWS resources. 14. What is the principle of least privilege? - ANSWER Grant only the permissions required to perform a specific task. 15. What is AWS Identity and Access Management (IAM)? - ANSWER AWS IAM is a web service that enables Amazon Web Services customers to manage users and user permissions in AWS. 16. What can you do with IAM? - ANSWER You can centrally manage users, security credentials such as access keys, and permissions that control which AWS resources users can access. 17. How can you manage IAM Users and their access? - ANSWER You can create Users and assign them individual security credentials (access keys, passwords, and multi-factor authentication devices). 18. True or False? You can manage permissions to control which operations a User can perform - ANSWER True 19. What is an IAM Role? - ANSWER An IAM Role is similar to a User, in that it is an AWS Identity with permissions policies that determine what the identity can and cannot do in AWS. However, instead of being uniquely associated with one person, a Role is intended to be assumable by anyone who needs it. 20. True or False? A role can only be assigned to one user. - ANSWER False! A role is intended to be assumable by anyone who needs it. 21. How can you manage federated users and their permission? - ANSWER You can enable identity federation to allow existing users in your enterprise to access the AWS Management Console, to call AWS APIs and to access resources, without the need to create an IAM user for each identity. 22. What is the best practice for securing the AWS root account? - ANSWER Enable MFA, use a strong password, and avoid using it for daily tasks. 23. Who has full access to all AWS services and resources by default? - ANSWER The AWS account root user. 24. Should the root account be used for daily administrative tasks? - ANSWER No. Use it only for specific account-level tasks and protect it with MFA.

Content preview

AWS IAM Fundamentals for Cloud Practitioner:
Users, Groups, Policies, and Security Complete
Exam Study Questions with Verified Answers

1. What does IAM stand for? - ANSWER Identity and Access Management


2. What is AWS IAM? - ANSWER A service used to securely control access
to AWS resources.


3. What are the three main IAM components? - ANSWER Users, Groups,
Roles.


4. Should the root account be used for daily administrative tasks? - ANSWER
No. Use it only for specific account-level tasks and protect it with MFA.


5. Which of the following are benefits of using Amazon EC2 roles? (Choose 2
answers)


a. No policies are required.
b. Credentials do not need to be stored on the Amazon EC2 instance.
c. Key rotation is not necessary. d. Integration with Active Directory is
automatic. -
ANSWER B, C. Amazon EC2 roles must still be assigned a policy.
Integration with Active Directory involves integration between Active
Directory and IAM via SAML.


6. Which of the following are based on temporary security tokens? (Choose 2
answers)

, a. Amazon EC2 roles
b. MFA
c. Root user
d. Federation -
ANSWER A, D. Amazon EC2 roles provide a temporary token to
applications running on the instance; federation maps policies to
identities from other sources via temporary tokens.


7. Your security team is very concerned about the vulnerability of the IAM
administrator user accounts (the accounts used to configure all IAM features
and accounts). What steps can be taken to lock down these accounts?
(Choose 3 answers)


a. Add multi-factor authentication (MFA) to the accounts.
b. Limit logins to a particular U.S. state.
c. Implement a password policy on the AWS account.
d. Apply a source IP address condition to the policy that only grants
permissions when the user is on the corporate network.
e. Add a CAPTCHA test to the accounts. -
ANSWER A, C, D


8. What is the format of an IAM policy? - ANSWER JSON


9. Who has full access to all AWS services and resources by default? -
ANSWER The AWS account root user.


10.What is an IAM User? - ANSWER A permanent identity used by a person
or application with long-term credentials.

, 11.What is an IAM Group? - ANSWER A collection of IAM users that share
the same permissions.


12.Can IAM Groups contain other IAM Groups? - ANSWER No. IAM Groups
can contain users but not other groups.


13.What is an IAM Policy? - ANSWER A JSON document that defines
allowed or denied actions on AWS resources.


14.What is the principle of least privilege? - ANSWER Grant only the
permissions required to perform a specific task.


15.What is AWS Identity and Access Management (IAM)? - ANSWER AWS
IAM is a web service that enables Amazon Web Services customers to
manage users and user permissions in AWS.


16.What can you do with IAM? - ANSWER You can centrally manage users,
security credentials such as access keys, and permissions that control which
AWS resources users can access.


17.How can you manage IAM Users and their access? - ANSWER You can
create Users and assign them individual security credentials (access keys,
passwords, and multi-factor authentication devices).


18.True or False?
You can manage permissions to control which operations a User can perform -
ANSWER True

Document information

Uploaded on
July 23, 2026
Number of pages
24
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$11.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
DrSammuel
5.0
(1)
Sold
7
Followers
0
Items
917
Last sold
1 week ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions