Pregunta
- Which statements about AWS Identity and Access Management (IAM) policies are
accurate? (Select TWO.)
Identity-based policies are attached to a user, group, or role.
Identity-based policies can only be attached to a single entity.
Access control lists (ACLs) are a form of resource-based policies.
Resource-based policies allow access by default.
Resource-based policies are attached to a user, group, or role.
accurate? (Select TWO.)
Ask by Smith Gibbs. in South Africa
Mar 22,2025
Solución de inteligencia artificial de Upstudy
Respuesta verificada por el tutor
Responder
The two accurate statements are:
- Identity-based policies are attached to a user, group, or role.
- Access control lists (ACLs) are a form of resource-based policies.
Solución
Let’s analyze each statement regarding AWS Identity and Access Management (IAM) policies to determine which ones are accurate:
-
Identity-based policies are attached to a user, group, or role.
- This statement is accurate. Identity-based policies are indeed attached to IAM identities such as users, groups, or roles.
-
Identity-based policies can only be attached to a single entity.
- This statement is inaccurate. Identity-based policies can be attached to multiple entities (users, groups, or roles).
-
Access control lists (ACLs) are a form of resource-based policies.
- This statement is accurate. ACLs are indeed a type of resource-based policy that controls access to resources.
-
Resource-based policies allow access by default.
- This statement is inaccurate. Resource-based policies do not allow access by default; they explicitly define who has access to the resource.
-
Resource-based policies are attached to a user, group, or role.
- This statement is inaccurate. Resource-based policies are attached to resources (like S3 buckets or IAM roles), not directly to users, groups, or roles.
Based on this analysis, the two accurate statements are:
- Identity-based policies are attached to a user, group, or role.
- Access control lists (ACLs) are a form of resource-based policies.
Respondido por UpStudy AI y revisado por un tutor profesional
Como
error msg


Bonus Knowledge
Identity-based policies are indeed powerful tools in AWS IAM! They can be attached to users, groups, or roles, granting permissions based on the identity rather than the resource. This means that you can manage permissions centrally, making it easier to control access across your AWS resources.
On the other hand, resource-based policies can be seen as the guardian angels of security. These policies are attached directly to resources (like S3 buckets or Lambda functions) and specify who can access them. Interestingly, they allow for greater flexibility, as you can grant access to users from other accounts or even anonymize permissions for public access, typically denying by default unless specified otherwise.

¡Prueba Premium ahora!
¡Prueba Premium y hazle a Thoth AI preguntas de matemáticas ilimitadas ahora!
Quizas mas tarde
Hazte Premium