QuestionQ5

Identity and Access Management

A company uses AWS IAM Identity Center to control access to its AWS accounts. The accounts belong to an organization in AWS Organizations.

A security engineer must establish delegated administration of IAM Identity Center in the organization’s management account.

Which combination of steps should the security engineer complete in IAM Identity Center before setting up delegated administration?

Choose three
Explanation

IAM Identity Center delegated-administration best practices are to grant least-privilege access to the highly privileged management account, use dedicated permission sets for that account because delegated administrators cannot modify permission sets provisioned there, and assign users directly to management-account permission sets rather than groups. Direct user assignments reduce the risk that group-membership changes grant unintended access to the management account.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!