A company needs to allow users in one AWS account to access resources in a different AWS account. The users currently lack permission to access those resources. Which IAM feature should be used?
Choose an answer
Tap an option to check your answer.
Correct answer: IAM role.
Why this is the answer
An IAM role is the correct feature for cross-account access because it defines a set of permissions that can be assumed by an authorized entity, such as a user in another AWS account. When a user assumes a role, they temporarily gain the permissions associated with that role, allowing them to access resources in the target account without having their own credentials in that account. IAM groups are collections of IAM users and are used to manage permissions for multiple users within a single account, not for cross-account access. IAM tags are key-value pairs used for organizing and identifying AWS resources, not for granting access. IAM Access Analyzer helps identify resources shared with external entities, but it doesn't grant the access itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed