A SysOps administrator must grant a set of IAM users access to AWS services by attaching a policy to them, and also needs the ability to modify that policy and create new versions. Which combination of steps meets these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Add the users to an IAM group and attach the reusable policy to the group., Create a customer managed policy that you can edit and version..
Why this is the answer
To efficiently manage permissions for multiple users, adding them to an IAM group and attaching a policy to that group is the recommended approach. This allows for centralized management; any user added to the group automatically inherits the group's permissions. Creating a customer managed policy is essential because it allows the administrator to define, edit, and version the policy according to specific organizational needs. AWS managed policies are predefined by AWS and cannot be modified. Inline policies are attached directly to a user, group, or role and cannot be reused or easily versioned across multiple entities, making them impractical for managing a set of users. IAM service-linked roles are predefined by AWS for specific services and cannot be used to group IAM users.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed