Topic module

Shared Responsibility, IAM and Access Control

Security and Compliance questions heavily test the shared responsibility model, IAM users, groups, roles, policies, MFA, and least privilege.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AWS Cloud Practitioner

Treat each question as a service-selection or responsibility decision: identify the business need, AWS responsibility, customer configuration, and best-fit service.

Core concepts

Concept 1

AWS is responsible for security of the cloud; customers are responsible for security in the cloud.

Exam cue: Classify the task as AWS responsibility or customer responsibility.

Concept 2

IAM controls authentication and authorization for AWS identities and should follow least privilege.

Exam cue: Use IAM policies and least privilege for authorization questions.

Concept 3

Roles are preferred for temporary delegated access by AWS services, applications, federated users, or cross-account use cases.

Exam cue: Use roles for temporary delegated access.

Risk pitfalls and guardrails

Sharing the root account for daily administration.

Guardrail: Avoid answers that ignore customer configuration, choose unmanaged services when managed services fit, or use billing reports when proactive alerts are required.

Granting AdministratorAccess when a narrower policy is enough.

Guardrail: Avoid answers that ignore customer configuration, choose unmanaged services when managed services fit, or use billing reports when proactive alerts are required.

Assuming AWS configures customer IAM permissions automatically.

Guardrail: Avoid answers that ignore customer configuration, choose unmanaged services when managed services fit, or use billing reports when proactive alerts are required.

Memory anchors

Shared Responsibility

AWS secures the cloud infrastructure while customers secure their data, identity, configuration, and workloads.

IAM User

An IAM user is a long-term identity in an AWS account.

IAM Group

An IAM group attaches permissions to multiple IAM users.

IAM Role

An IAM role provides temporary credentials for delegated access.

IAM Policy

An IAM policy defines allowed or denied actions on AWS resources.

Least Privilege

Least privilege grants only the permissions needed for a task.

MFA

Multi-factor authentication adds another verification factor beyond a password.

Root User

The root user has full account access and should be protected and rarely used.

Federation

Federation lets external identities access AWS through trusted identity integration.

Temporary Credentials

Temporary credentials expire and reduce long-term credential exposure.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A company runs an application on Amazon EC2. Who is responsible for patching the guest operating system?

For an Amazon RDS database, which task is AWS responsible for under the shared responsibility model?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.