If an AWS managed IAM policy doesn’t provide needed permissions for users, what is the appropriate way to fix this?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a custom IAM policy..
Why this is the answer
When an AWS managed IAM policy doesn't grant the specific permissions required, the most appropriate solution is to create a custom IAM policy. This allows you to define precise permissions tailored to your users' needs, adhering to the principle of least privilege. You can attach this custom policy directly to users, groups, or roles. Enabling AWS Shield Advanced is incorrect because it's a DDoS protection service, unrelated to managing user permissions. Deploying a third-party WAF rule from the AWS Marketplace is also incorrect as WAFs protect web applications from common exploits, not manage IAM permissions. Using AWS KMS to generate a customer-managed key is incorrect because KMS is for encryption key management, not for defining user access rights.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed