IAM Flashcards
IAM provide
centralized control, shared access to aws account, granular permissions, Federation, MFA, temp access to users devices and services , setup password rotation policy, PCI DSS
Policy
Controls what a user/group/role is able to do
IAM users signin link
.siginin.aws.amazon.com/console
Virtual MFA
google authentication app
Access types
Programmatic(access key id, access key), Management console(password)
Secret access key for programmatic access
is visible only one time. It cannot be used to login to console.
New users
Have no permission when they are first created
What command should you run on a running instance if you want to view its user data (that is used at launch)?
curl http://169.254.169.254/latest/user-data