AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A company has 50 IAM users who all require the same set of permissions to manage Amazon S3 buckets. The permissions are expected to change periodically as business needs evolve. Which approach minimizes administrative overhead?
- AAttach an identical IAM policy individually to each of the 50 users
- BCreate a separate IAM role for each of the 50 users and have them assume it manually
- CStore the required permissions in AWS Config rules so they apply automatically
- DCreate an IAM group with the required policy attached, and add all 50 users to that group
Show answer & explanationAnswer & explanation
Correct answer: D. Create an IAM group with the required policy attached, and add all 50 users to that group
IAM groups let administrators attach a policy once and manage permissions for many users centrally; updating the group policy automatically applies to all members. Attaching policies individually multiplies maintenance work, and AWS Config does not grant IAM permissions.
Why the other options are wrong
- A. Requires updating 50 separate policies whenever permissions change.
- B. Roles are meant for temporary access or service use, not routine group permission management.
- C. AWS Config evaluates resource compliance; it does not grant or manage IAM permissions.
IAM Groups
IAM groups let you attach policies to multiple users at once, simplifying permission management for users with similar access needs.
- Users can belong to multiple groups
- Policies attached to a group apply to all members
- Best practice: attach policies to groups, not individual users
Memory trick: Group first, individual last