AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A cloud administrator wants to create a single IAM policy document that can be attached to multiple users, groups, and roles, and that can be updated in one place so every attached identity automatically receives the change. Which type of IAM policy should the administrator create?
- AManaged policy
- BInline policy
- CResource-based policy
- DService control policy
Show answer & explanationAnswer & explanation
Correct answer: A. Managed policy
A managed policy is a standalone policy that can be attached to multiple IAM identities and updated centrally, with changes propagating to all attachments. Inline policies are embedded in a single identity and must be edited individually, resource-based policies attach to resources rather than identities, and SCPs apply only within AWS Organizations to set permission ceilings.
Why the other options are wrong
- B. Inline policies are tied to one specific identity and are not reusable.
- C. Resource-based policies are attached to resources like S3 buckets, not identities.
- D. SCPs set maximum permissions across an organization, not identity-level grants.
IAM Managed Policy
A standalone, reusable IAM policy that can be attached to multiple users, groups, or roles and updated centrally.
- AWS managed policies are created and maintained by AWS
- Customer managed policies are created and maintained by the account owner
- Editing a managed policy updates permissions everywhere it's attached
Memory trick: Managed policies are the reusable stamp you attach anywhere.