AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
A large enterprise wants its cloud security team to set a maximum permission ceiling for a delegated administrator IAM role, ensuring that even if the role's attached policy is later broadened, the effective permissions can never exceed a defined limit. Which IAM feature should be used?
- AIAM group policy
- BService control policy (SCP)
- CResource-based policy
- DIAM permissions boundary
Show answer & explanationAnswer & explanation
Correct answer: D. IAM permissions boundary
An IAM permissions boundary is an advanced feature that sets the maximum permissions an identity-based policy can grant to a user or role; the effective permissions are the intersection of the boundary and the identity policy. SCPs apply at the AWS Organizations account level, not to individual roles within an account. Group policies and resource-based policies do not function as a permission ceiling for a single role.
Why the other options are wrong
- A. Group policies grant permissions to group members but don't act as a ceiling.
- B. SCPs restrict entire AWS accounts/OUs in Organizations, not individual IAM roles directly.
- C. Resource-based policies attach to resources like S3 buckets, not as a permission limiter for a role.
IAM Permissions Boundary
An advanced IAM feature that defines the maximum permissions an identity-based policy can grant to a user or role.
- Effective permissions = intersection of boundary and identity policy
- Used for delegated administration
- Different from SCPs which apply at the Organizations account level
Memory trick: Boundary = the fence around a role's permissions