AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementHard
A security auditor discovers that an IAM role in an AWS account has a trust policy that allows `sts:AssumeRole` from any principal (`"AWS": "*"`). This role also has an attached IAM policy that grants administrative access (`AdministratorAccess`). The auditor is concerned about the security implications of this configuration. What is the MOST immediate and significant risk posed by this trust policy, even if the attached IAM policy has specific resource constraints?
- AIt prevents the application of Service Control Policies (SCPs) to this specific role.
- BIt enables unauthorized access to the AWS Management Console for unauthenticated users.
- CIt allows any AWS service to assume the role and perform administrative actions.
- DIt permits any authenticated AWS principal from any account to assume the role, potentially leading to unauthorized administrative access.
Show answer & explanationAnswer & explanation
Correct answer: D. It permits any authenticated AWS principal from any account to assume the role, potentially leading to unauthorized administrative access.
A trust policy allowing `"AWS": "*"` means any authenticated AWS principal (user or role) from ANY AWS account can attempt to assume this role. Combined with `AdministratorAccess`, this opens the account to potential takeover by a malicious actor who gains control of any AWS principal, even from a different AWS account.
Why the other options are wrong
- A. SCPs apply at the organizational level and affect all IAM entities within member accounts, including roles with broad trust policies; the trust policy does not bypass SCPs.
- B. The `sts:AssumeRole` action requires an authenticated principal; it does not enable access for unauthenticated users.
- C. While services can assume roles, `"AWS": "*"` specifically refers to any authenticated AWS principal, not just services, and the primary risk is cross-account principal assumption.
IAM Role Trust Policy "AWS": "*"
A trust policy that allows any authenticated AWS principal from any AWS account to assume the role.
- Extremely dangerous when combined with high-privilege permissions.
- Should almost never be used in production environments.
- Can lead to cross-account compromise if a principal in another account is compromised.
Memory trick: Think of leaving your safe deposit box open for anyone with 'an ID' (any AWS principal) to access.