exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 237 discussion

In the context of IAM roles for Amazon EC2, which of the following NOT true about delegating permission to make API requests?

  • A. You cannot create an IAM role.
  • B. You can have the application retrieve a set of temporary credentials and use them.
  • C. You can specify the role when you launch your instances.
  • D. You can define which accounts or AWS services can assume the role.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
amministrazione
8 months, 3 weeks ago
A. You cannot create an IAM role.
upvoted 1 times
...
SkyZeroZx
1 year, 10 months ago
Selected Answer: A
The option that is NOT true about delegating permission to make API requests using IAM roles for Amazon EC2 is: A. You cannot create an IAM role. This statement is incorrect. You can create IAM roles in AWS to delegate permissions to entities such as EC2 instances, applications, or AWS services. IAM roles are used to grant permissions and allow these entities to make API requests on your behalf.
upvoted 1 times
...
Sizuma
2 years, 8 months ago
A right Explanation: Amazon designed IAM roles so that your applications can securely make API requests from your instances, without requiring you to manage the security credentials that the applications use. Instead of creating and distributing your AWS credentials, you can delegate permission to make API requests using IAM roles as follows: Create an IAM role. Define which accounts or AWS services can assume the role. Define which API actions and resources the application can use after assuming the role. Specify the role when you launch your instances. Have the application retrieve a set of temporary credentials and use them.
upvoted 1 times
...
Ddssssss
2 years, 11 months ago
Is this a double negative? Can an API authorization create an AMI role or not?
upvoted 1 times
...
Kuntazulu
3 years ago
Selected Answer: A
The role you are delegating to has to exist for delegating authorization to perform API calls
upvoted 2 times
...
ideoignus
3 years, 1 month ago
Selected Answer: C
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_switch-role-ec2.html Role cannot be passed while launching, only through instance profile
upvoted 1 times
Kuntazulu
3 years ago
Re-read the question, no one mentioned passing roles when launching
upvoted 2 times
...
...
adsdadasdad
3 years, 2 months ago
Selected Answer: A
A is only logical answer
upvoted 2 times
...
Serial_X25
3 years, 2 months ago
D is correct IMO. take a look at https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_switch-role-ec2.html. Go to IAM console, select IAM->Roles->Create Role, then you need to select the Trusted entity type, it can be AWS service or AWS account between others, in case of AWS services the commom use cases mention EC2, Lambda and other services, but not accounts. So I believe that "accounts" is the word in the wrong place here at letter D. Off course I'd like to hear some feedback from you Guys. Thanks.
upvoted 1 times
tobstar86
3 years, 1 month ago
Accounts (end all their belonging IAM identities) can assume a role. https://aws.amazon.com/premiumsupport/knowledge-center/iam-assume-role-cli/ "For example, a principal similar to arn:aws:iam::123456789012:root allows all IAM identities of the account to assume that role." This would rule out D. A, seems to be the obvious choice here.
upvoted 1 times
...
...
manan728
3 years, 4 months ago
This is how you create IAM role:https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create.html
upvoted 1 times
...
cldy
3 years, 5 months ago
A. You cannot create an IAM role.
upvoted 1 times
vishg
3 years, 3 months ago
Not clear. Describe, please.
upvoted 1 times
bobsmith2000
3 years, 1 month ago
B. Correct. That is precisely what roles are designed to be used for. C. Correct. You specify a role when you launch an instance via console, not an instance profile (it's managed by aws under the hood). D. Correct. In a trusted policy an account or an aws service can be specified. So it's only A that has left.
upvoted 2 times
...
...
...
01037
3 years, 6 months ago
A is Correct
upvoted 2 times
...
M_Asep
3 years, 6 months ago
A is Correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago