Open cardosec

Case 98102A · Cloud · L3 Applied

Least-Privilege IAM

Practise as: Explain it · Interview

Interview questionHow do you get an AWS account from wildcard policies to least privilege without breaking production?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Wildcards like Action "*" or Resource "*" turn any credential leak into full account compromise
  2. Use access analysis (IAM Access Analyzer, last-accessed data) to generate policies from observed usage
  3. Prefer roles with short-lived credentials over long-lived access keys for humans and workloads
  4. Guardrails: SCPs or org policies deny dangerous actions account-wide; permission boundaries cap delegated roles
  5. Roll out iteratively with monitoring for AccessDenied spikes, not a big-bang rewrite

If the interviewer pushes back

  • How do permission boundaries differ from SCPs in what they can and cannot restrict?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.