iAM Flashcards
iAM
1
Q
Is a global service. User is single entity. Groups only contain users
A
iAM Users and Groups
2
Q
Is attached a policy which defines the access control to a resource
Structure is Effect (Allow/Deny), Action(API calls), Resource (What resource access is allowed)
A
iAM Policies
3
Q
Used by AWS services to access resources on users behalf. Permissions are assigned to the iAM role in order to do that.E.g. - EC2 instance roles, Lambda function roles, CloudFormation roles
A
iAM Role
4
Q
- Add new role
- Choose the AWS service like EC2, Lambda, etc…
- Attach a policy
A
iAM Role application