Study. uk . com
  1. Home
  2. All questions
  3. Question 83

AWS Certified Solutions Architect study material · question 83 of 500

An administrator must let a team lead manage IAM permissions in an account without being able to widen their own access. Which mechanism does this?

  1. An access control list on the IAM service
  2. A permissions boundary on the entities the team lead can create
  3. A service control policy on the account
  4. A session policy passed at sign-in
Show the answer

Answer: B. A permissions boundary on the entities the team lead can create

Permissions boundaries are how permission-management duties are delegated inside an account without allowing privilege escalation.

Source: Security best practices in IAM (Amazon Web Services) — Use permissions boundaries to delegate permissions management

Challenge yourself on this topic → Study as cards