AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium

A company is implementing a new compliance requirement that mandates all access to AWS resources must be explicitly allowed. If an action is not explicitly allowed by any policy, it must be denied. The security team wants to ensure that this principle is applied consistently across all IAM users, groups, and roles within a specific AWS account. How can they achieve this?

  1. AThis is AWS's default behavior; no additional configuration is needed.
  2. BAttach a permissions boundary to all IAM principals that explicitly denies all actions.
  3. CEnsure all IAM policies use an explicit `Deny` statement for any action not explicitly `Allow`ed.
  4. DConfigure an AWS Organizations Service Control Policy (SCP) to explicitly deny all actions by default.
Show answer & explanation

Correct answer: A. This is AWS's default behavior; no additional configuration is needed.

AWS IAM operates on an 'implicit deny' principle. If an action is not explicitly allowed by any attached policy (identity-based, resource-based, or permission boundary), it is automatically denied. Therefore, no additional configuration is needed to enforce this specific requirement.

Why the other options are wrong

  • B. A permissions boundary sets the maximum permissions an identity can have; it doesn't change the fundamental implicit deny behavior, and applying a blanket `Deny` boundary would prevent all actions.
  • C. Explicit `Deny` statements are used to override `Allow` statements. The requirement is for actions not explicitly allowed to be denied, which is the default 'implicit deny' behavior.
  • D. SCPs define maximum permissions at an organizational level, but the core IAM evaluation logic within an account already enforces implicit deny.

IAM Policy Evaluation Logic: Implicit Deny

If an AWS API action is not explicitly allowed by any applicable policy, it is implicitly denied by default.

  • Explicit Deny always overrides Explicit Allow.
  • Implicit Deny is the default state if no Allow is present.
  • Understanding this logic is crucial for secure IAM policy design.

Memory trick: Think of a bouncer at a club: if your name isn't on the 'allowed' list, you're automatically 'denied' entry.

More Domain 4: Identity and Access Management questions