QuestionQ23

Identity and Access Management

A company has engaged a third party to audit multiple AWS accounts. Cross-account IAM roles have been created in every account being audited to support the audit. The auditor is experiencing difficulty accessing some accounts.

Which of the following could be causing this issue?

Choose three
Explanation

Assuming a cross-account IAM role requires permission to perform sts:AssumeRole on the target role and the correct target role ARN. When the target role’s trust policy requires an external ID for third-party access, the AssumeRole request must include the exact required external ID; otherwise, AWS denies the request.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!