A security engineer must restrict a contractor’s IAM user to Amazon EC2 console access only and prevent access to all other AWS services, even if additional permissions are granted through IAM group membership. What should the security engineer do to meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an IAM permissions boundary policy that allows only Amazon EC2 access. Attach the permissions boundary to the contractor’s IAM user..
Why this is the answer
A permissions boundary sets the maximum permissions an IAM entity (user or role) can have. Even if an identity-based policy grants broader permissions, the permissions boundary restricts the effective permissions to only what it allows. In this scenario, creating a permissions boundary that permits only EC2 actions and attaching it to the contractor's IAM user ensures that the user can never access other AWS services, regardless of any group memberships or additional inline policies. Attaching an inline policy might be overridden by group policies. Adding the
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed