AWS Cloud Practitioner (CLF-C02) Notes, Part 2: IAM Domain 2: Security & Compliance (30% of the exam) IAM (Identity and Access Management) controls who can sign in (authentication) and what they're allowed to do (authorization). It's a global service, and it's free. 1. The building blocks Identity What it is Key rules --------- Root user The identity created with the account (email + password), with full, unrestricted access Use it only for tasks that require it. Enable MFA. Never create access keys for it or share it IAM user One person or application with its own long-term credentials One person = one IAM user. Never share users IAM group A set of users that share the same permissions Contains users only; groups can't be nested. A user can be in several groups or in none IAM role A set of permissions that a trusted entity assumes, getting temporary credentials Used by AWS services (EC2, Lambda), for cross-account access, and for federated users Policy A JSON document that allows or denies actions on resources Attach it to users, groups or roles, and follow least privilege A new user with no policy can do nothing, because everything is denied by default. An explicit Deny always overrides an Allow. 2. Policies Element Purpose ------ Version The policy language version; always "2012-10-17" Statement One or more permission rules (required) Effect Allow or Deny Action The API calls covered, e.g. s3:GetObject or ec2:Describe Resource The resources the actions apply to Principal Who the policy applies to (used in resource-based policies such as S3 bucket policies) Condition Optional limits on when it applies, e.g. source IP or MFA present Sid / Id Optional identifiers Policy types: AWS managed (prebuilt), customer managed (your own, reusable), and inline (embedded in a single identity). Prefer managed policies over inline ones. Inheritance: a user gets the policies of every group they belong to, plus any attached to them directly. Least privilege: grant only what the job needs. 3. Protecting sign-in Password policy settings: minimum length; required character types (uppercase, lowercase, numbers, symbols); letting users change their own password; password expiration; preventing password reuse. MFA combines something you know (the password) with something you have (a device). If the password leaks, the account still isn't compromised. MFA device Examples ------ Virtual authenticator app Google Authenticator, Authy, Microsoft Authenticator Passkey / FIDO security key YubiKey; one key can protect several users Hardware TOTP token A key fob from a third-party vendor 4. Ways to access AWS Method Credentials Used for --------- Management Console Password (+ MFA) The web-based graphical interface AWS CLI Access keys Commands and scripts in a terminal (open source, built on the Python SDK) AWS SDKs Access keys Calling AWS from application code; language libraries (Python, Java, JavaScript, .NET, Go…) plus mobile and IoT SDKs AWS CloudShell Your existing console session A terminal in the browser with the CLI preinstalled Access keys come in two parts: an access key ID (like a username) and a secret access key (like a password). They're long-term credentials that you create in the console. The secret is shown only once, at creation. A user can have at most two access keys, which lets you rotate them without downtime. Never share access keys or put them in code; on AWS, use a role instead. 5. Roles for AWS services When an AWS service has to act on your behalf, you give it a role: An EC2 instance role, attached through an instance profile A Lambda execution role A CloudFormation service role With a role, no long-term keys are stored on the instance, and the temporary credentials rotate automatically. Roles also handle cross-account access: users in account A assume a role in account B. 6. Auditing tools Tool Scope What it tells you --------- IAM credential report The whole account (a downloadable CSV) Every user's password, access keys and MFA status, and when keys were last used or rotated IAM Access Advisor One user, group or role Which services it can access and when it last used them, so you can remove unused permissions IAM Access Analyzer An account or an organization Which resources are shared with external accounts or the public, plus unused access 7. Best practices Don't use the root user except for account setup and tasks that only root can do. One person = one IAM user. Never share users or access keys. Put users in groups and attach permissions to the groups. Set a strong password policy and require MFA, starting with the root user. Use roles for AWS services, not access keys. Use access keys only for programmatic access, and rotate them. Audit with the credential report and Access Advisor. For workforce users, AWS's current guidance favors IAM Identity Center with temporary credentials. Exam questions still expect one IAM user per person. 8. Shared responsibility for IAM AWS You ------ Infrastructure and…