
Ultimate access to all questions.
A development team lead is tasked with managing access for IAM principals within the team. Initially, she granted users excessive privileges to encourage experimentation and innovation. As the project progresses, she now aims to minimize these permissions to only what is necessary for the team to complete their tasks efficiently.
Which of the following methods will assist her in identifying any unused IAM roles and subsequently removing them without causing any disruption to services?
A
IAM Access Analyzer
B
Amazon Inspector
C
Access Advisor feature on IAM console
D
AWS Trusted Advisor
Explanation:
Access Advisor feature on IAM console- To help identify the unused roles, IAM reports the last-used timestamp that represents when a role was last used to make an AWS request. Your security team can use this information to identify, analyze, and then confidently remove unused roles. This helps improve the security posture of your AWS environments. Additionally, by removing unused roles, you can simplify your monitoring and auditing efforts by focusing only on roles that are in use.
Incorrect options:
AWS Trusted Advisor - AWS Trusted Advisor is an online tool that provides you real-time guidance to help you provision your resources following AWS best practices on cost optimization, security, fault tolerance, service limits, and performance improvement.
IAM Access Analyzer - AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk.
Amazon Inspector - Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices.
Reference:
https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor-view-data.html