ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 703 - CLF-C02 discussion

Report
Export

In which situations should a company create an 1AM user instead of an 1AM role? (Select TWO.)

A.
When an application that runs on Amazon EC2 instances requires access to other AWS services
Answers
A.
When an application that runs on Amazon EC2 instances requires access to other AWS services
B.
When the company creates AWS access credentials for individuals
Answers
B.
When the company creates AWS access credentials for individuals
C.
When the company creates an application that runs on a mobile phone that makes requests to AWS
Answers
C.
When the company creates an application that runs on a mobile phone that makes requests to AWS
D.
When the company needs to add users to 1AM groups
Answers
D.
When the company needs to add users to 1AM groups
E.
When users are authenticated in the corporate network and want to be able to use AWS without having to sign in a second time
Answers
E.
When users are authenticated in the corporate network and want to be able to use AWS without having to sign in a second time
Suggested answer: B, D

Explanation:

An IAM user is created when the company needs to provide unique credentials (username and password) to individuals who need access to the AWS Management Console or programmatic access (using access keys) to AWS services.

B . When the company creates AWS access credentials for individuals: Correct, as an IAM user is created to provide credentials for specific individuals.

D . When the company needs to add users to IAM groups: Correct, as IAM users can be added to groups to apply permissions and policies at a group level.

A . When an application that runs on Amazon EC2 instances requires access to other AWS services: Incorrect, as an IAM role is more appropriate for applications running on EC2 to assume temporary credentials.

C . When the company creates an application that runs on a mobile phone that makes requests to AWS: Incorrect, as using Cognito or a role with temporary credentials is more suitable.

E . When users are authenticated in the corporate network and want to be able to use AWS without having to sign in a second time: Incorrect, as this use case typically involves IAM roles combined with AWS Single Sign-On (SSO).

AWS Cloud References:

IAM Users and Groups

IAM Roles

asked 16/09/2024
Siegfried Paul
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first