Case 98102A · Cloud · L3 Applied
Least-Privilege IAM
Practise as: Explain it · Interview
Interview questionHow do you get an AWS account from wildcard policies to least privilege without breaking production?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Wildcards like Action "*" or Resource "*" turn any credential leak into full account compromise
- Use access analysis (IAM Access Analyzer, last-accessed data) to generate policies from observed usage
- Prefer roles with short-lived credentials over long-lived access keys for humans and workloads
- Guardrails: SCPs or org policies deny dangerous actions account-wide; permission boundaries cap delegated roles
- Roll out iteratively with monitoring for AccessDenied spikes, not a big-bang rewrite
If the interviewer pushes back
- How do permission boundaries differ from SCPs in what they can and cannot restrict?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.