Question 1 · choose 1
Developers in a workload account must be able to create IAM roles for their own Lambda functions without waiting for the security team. Security requires that no role a developer creates can ever have more permissions than an approved policy named AppBoundary, and that developers cannot weaken this control. What should the DevOps engineer do?
- AAttach an SCP to the account that denies iam:CreateRole for every principal except the security team's role
- BAllow role creation only with iam:PermissionsBoundary set to AppBoundary, and deny edits to AppBoundary and boundary removal
- CSet AppBoundary as the permissions boundary of the developers' own role and allow them to create and pass roles without any condition
- DRequire developers to assume their role with a session policy equal to AppBoundary whenever they create a role
Show the answer and why
AAttach an SCP to the account that denies iam:CreateRole for every principal except the security team's role
Incorrect
This keeps the control but takes role creation away from the developers, which is the opposite of the request.
BAllow role creation only with iam:PermissionsBoundary set to AppBoundary, and deny edits to AppBoundary and boundary removal
Correct
A condition on iam:PermissionsBoundary lets the delegate create principals only with the required boundary, and denying edits to the boundary policy and its removal stops the delegate from escaping it.
CSet AppBoundary as the permissions boundary of the developers' own role and allow them to create and pass roles without any condition
Incorrect
The boundary limits the developers' role, but the roles they create can carry any policy, so they could create a more powerful role and use it.
DRequire developers to assume their role with a session policy equal to AppBoundary whenever they create a role
Incorrect
A session policy limits only that session. It places no limit on the permissions of the roles created during it.
Permissions boundaries are the IAM tool for delegating permission management. The delegate may create principals only if they carry the approved boundary, and must not be able to edit or detach that boundary.
AWS documentation