AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium

A security auditor discovers that an IAM role named 'DevAdminRole' in an AWS account has a trust policy that allows an external AWS account (Account ID: 111122223333) to assume the role. The auditor also finds that the 'DevAdminRole' has an attached inline policy that grants 's3:*' permissions to all S3 buckets. The external account should no longer have any access. What is the MOST effective way to revoke access for the external account while ensuring the 'DevAdminRole' can still be used by trusted internal users?

  1. ADisable the 'DevAdminRole' temporarily using an AWS Organizations Service Control Policy (SCP).
  2. BAttach an explicit deny IAM policy to the 'DevAdminRole' for Account ID 111122223333.
  3. CModify the trust policy of the 'DevAdminRole' to remove Account ID 111122223333 from the principal.
  4. DDelete the inline policy granting 's3:*' permissions from the 'DevAdminRole'.
Show answer & explanation

Correct answer: C. Modify the trust policy of the 'DevAdminRole' to remove Account ID 111122223333 from the principal.

The trust policy of an IAM role defines who can assume that role. By modifying the trust policy to remove the external account ID from the 'Principal' element, you directly revoke the external account's ability to assume the 'DevAdminRole', without affecting the role's permissions or its use by other trusted principals.

Why the other options are wrong

  • A. Using an SCP at the organizational level would affect all accounts under that OU (or the root) and would disable the role for *all* users, including internal ones, which is not desired.
  • B. Attaching an explicit deny policy is an option, but modifying the trust policy is more precise and cleaner as it directly removes the ability to assume the role in the first place, rather than allowing assumption and then denying actions.
  • D. Deleting the inline policy would revoke S3 access for *all* users of 'DevAdminRole', not just the external account, which is not the specific requirement.

IAM Role Trust Policy

An IAM role's trust policy specifies which principals (users, roles, or AWS services) are allowed to assume that role.

  • Defines the 'who' (principal) that can assume the role.
  • Must grant `sts:AssumeRole` action.
  • Separate from the permissions policy attached to the role (the 'what' they can do).

Memory trick: Trust Policy is the gatekeeper for who can assume the role.

More Domain 4: Identity and Access Management questions