AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementEasy
A security auditor discovers that an IAM role in an AWS account has a trust policy that allows an external AWS account (Account B) to assume it. However, the external account is no longer managed by the company. The auditor needs to revoke access for Account B immediately and ensure no other external accounts can assume this role in the future, while still allowing existing internal trusted entities to assume the role. Which action should the auditor take?
- ADisable the IAM role temporarily and review its permissions later.
- BDelete the IAM role and recreate it with a new trust policy.
- CAttach an explicit deny IAM policy to the IAM role that denies `sts:AssumeRole` for Account B.
- DModify the IAM role's trust policy to remove Account B's ARN from the `Principal` element and ensure only internal accounts are listed.
Show answer & explanationAnswer & explanation
Correct answer: D. Modify the IAM role's trust policy to remove Account B's ARN from the `Principal` element and ensure only internal accounts are listed.
The trust policy of an IAM role explicitly defines which principals (users, roles, or AWS accounts) are allowed to assume that role. Modifying the trust policy to remove the external account's ARN is the direct and most effective way to revoke its access. Ensuring only internal accounts are listed prevents unintended external access.
Why the other options are wrong
- A. Disabling the role would prevent all entities, including internal ones, from assuming it, which is not the desired outcome as internal access still needs to be maintained. It's a temporary measure, not a permanent fix for the external access issue.
- B. Deleting and recreating the role would revoke access but is disruptive, requiring re-attaching policies and potentially updating any services or applications using the role. Modifying the trust policy is less disruptive.
- C. While an explicit deny policy can work, modifying the trust policy is more precise and foundational for role assumption. An explicit deny might also be more complex to manage if there are many external accounts involved.
IAM Role Trust Policy
A JSON policy attached to an IAM role that specifies which principals are allowed to assume the role.
- Defines the 'who' can assume the role.
- Uses the `Principal` element to specify trusted entities (AWS accounts, IAM users/roles).
- Must grant `sts:AssumeRole` action.
- Separate from the permissions policy, which defines 'what' the role can do.
Memory trick: Trust Policy is the gatekeeper, for who can assume the role's keeper.