Employees frequently move between teams and need permissions that match their job responsibilities. Which IAM construct should the company use to provide appropriate permissions with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: IAM roles.
Why this is the answer
IAM roles are the best choice because they provide temporary permissions that can be assumed by users, applications, or services. When an employee moves teams, they simply assume a different role, granting them the necessary permissions without modifying their individual user settings. This significantly reduces operational overhead compared to managing permissions directly on individual users. IAM user groups are useful for assigning permissions to a collection of users, but if users frequently change teams, you'd still need to move users between groups, which can be cumbersome. IAM instance profiles are specifically for EC2 instances to assume roles, not for human users. IAM policies for individual users would require manual updates for each user every time their responsibilities change, leading to high operational overhead and potential for errors.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed