Topic module

IAM, Federation and Multi-Account Access

Secure architecture questions test IAM roles, policies, federation, AWS IAM Identity Center, Organizations, SCPs, cross-account access, and least privilege.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AWS Solutions Architect Associate

Treat each question as an architecture tradeoff: identify security boundaries, failure modes, performance needs, data paths, and cost constraints before choosing services.

Core concepts

Concept 1

IAM, Federation and Multi-Account Access questions reward architecture tradeoff reasoning rather than picking the most familiar AWS service.

Exam cue: Identify the workload requirement, failure mode, data path, access boundary, and operational constraint.

Concept 2

The best answer maps requirements to security, resilience, performance, and cost constraints before choosing services.

Exam cue: Match the AWS service to the Well-Architected pillar the scenario is testing.

Concept 3

Eliminate answers that ignore shared responsibility, single points of failure, data movement, scaling behavior, or total cost.

Exam cue: Prefer managed, durable, least-privilege, multi-AZ, and right-sized designs when requirements call for them.

Risk pitfalls and guardrails

Choosing the most powerful service when a simpler managed service satisfies the requirement.

Guardrail: Avoid answers that use broad permissions, public data paths, single-AZ state, overbuilt compute, or commitment pricing without predictable usage.

Solving performance while ignoring security, availability, or cost constraints stated in the scenario.

Guardrail: Avoid answers that use broad permissions, public data paths, single-AZ state, overbuilt compute, or commitment pricing without predictable usage.

Assuming one Availability Zone, public access, or manual operations are acceptable without justification.

Guardrail: Avoid answers that use broad permissions, public data paths, single-AZ state, overbuilt compute, or commitment pricing without predictable usage.

Memory anchors

IAM Role

An IAM role provides temporary credentials and is preferred for AWS service and cross-account access.

Least Privilege

Least privilege grants only the permissions needed for the approved task.

IAM Policy

An IAM policy defines allowed or denied actions, resources, and conditions.

Permission Boundary

A permissions boundary sets the maximum permissions an identity-based policy can grant.

Identity Center

AWS IAM Identity Center centralizes workforce access to AWS accounts and applications.

Federation

Federation lets users authenticate through an external identity provider instead of local IAM users.

SCP

A service control policy sets maximum available permissions for accounts in AWS Organizations.

Cross Account Role

A cross-account role lets principals in one account access resources in another account.

Root User

The root user should be protected with MFA and avoided for routine administration.

Condition Key

A condition key limits policy effect based on context such as source IP, MFA, tag, or principal.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

An organization has 80 AWS accounts and uses an external identity provider. Employees need one portal and role-based access to assigned accounts without creating IAM users in each account. Which design is best?

A security team wants to prevent member accounts in one organizational unit from disabling CloudTrail, even if an account administrator grants the action locally. What should be applied?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.