exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 255 discussion

Exam question from Amazon's AWS-SysOps
Question #: 255
Topic #: 1
[All AWS-SysOps Questions]

An organization (Account ID 123412341234) has attached the below mentioned IAM policy to a user. What does this policy statement entitle the user to perform?

  • A. The policy allows the IAM user to modify all IAM user's credentials using the console, SDK, CLI or APIs
  • B. The policy will give an invalid resource error
  • C. The policy allows the IAM user to modify all credentials using only the console
  • D. The policy allows the user to modify all IAM user's password, sign in certificates and access keys using only CLI, SDK or APIs
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
WS Identity and Access Management is a web service which allows organizations to manage users and user permissions for various AWS services. If the organization (Account ID 123412341234) wants some of their users to manage credentials (access keys, password, and sing in certificates. of all IAM users, they should set an applicable policy to that user or group of users. The below mentioned policy allows the IAM user to modify the credentials of all IAM user's using only CLI, SDK or APIs. The user cannot use the AWS console for this activity since he does not have list permission for the IAM users.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Finger41
9 months, 1 week ago
All answers are wrong. ${aws:username} focalizes or restricts the policy to that of the logged user.
upvoted 1 times
...
waterzhong
10 months, 3 weeks ago
IT IS D.. https://aws.amazon.com/blogs/aws/variables-in-aws-access-control-policies/
upvoted 1 times
...
awscertified
1 year, 6 months ago
this question is wrong. None of the answers are correct. The Resource statement restricts the access to the logged user. So the user who has the policy attached can change his own credentials.
upvoted 4 times
awscertified
1 year, 6 months ago
similar example can be found here: https://aws.amazon.com/blogs/aws/variables-in-aws-access-control-policies/
upvoted 3 times
...
Golddust
1 year, 6 months ago
I agree with you here after reading your link. Variable substitution also simplifies allowing users to manage their own credentials. If you have many users, you may find it impractical to create individual policies that allow users to create and rotate their own credentials. With variable substitution, this becomes trivial to implement as a group policy. The following policy permits any IAM user to perform any of the key and certificate related actions on their own credentials. With the options available I will go with D
upvoted 1 times
...
...
karmaah
1 year, 6 months ago
Initially I thought, the user who logged in aws have the privs to modify only their pw,access & certificates only. if ${aws:username} mentioned in "Resource": will mean the current user who logged in AWS have the permission to modify all IAM users's password,access keys, certificates since profile used *
upvoted 3 times
...
awsnoob
1 year, 7 months ago
Ans is D: The policy allows the user to modify all IAM user’s password, sign in certificates and access keysusing only CLI, SDK or APIs
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago