The following are some exam tips for AWS IAM:
- The AWS IAM service is a global service. This means it is not region-specific. IAM entities such as users, groups, roles, and policies are the same across all regions. Once they are created, they are the same for all AWS regions.
- By default, newly created IAM users do not have any privileges to perform any tasks on AWS accounts. Users must be granted permission to access any service or perform any operation in AWS. User permissions are granted by either adding the user to a group with required permissions or by directly attaching an access policy to a user.
- IAM users can be a member of any IAM group, but an IAM group cannot be a member of any other IAM group. In other words, an IAM group cannot be nested.
- One user can be part of multiple policies and multiple policies can be attached to a single user.
- An IAM user password...