IAM is how AWS answers one question: who’s allowed to do what in your account. You create users, group them, write policies that spell out what they can touch, and hand out temporary permissions through roles.
Two things people miss
First, IAM is global — not tied to a Region. Second, the big one for the architect exam: when code on a server needs another AWS service, you don’t stash access keys on the server — you attach a role. The server borrows temporary credentials that rotate on their own, so there’s no secret to leak.
Test yourself
An application running on an EC2 instance needs to read objects from an S3 bucket. What is the most secure way to grant access?
- Store IAM user access keys on the instance
- Attach an IAM role to the EC2 instance
- Make the S3 bucket public
- Embed credentials in the application code
👉 Click to reveal the answer & explanation
Correct answer: B. An IAM role gives the instance temporary, auto-rotated credentials with no secret to store. Storing keys (A, D) exposes long-term credentials; a public bucket (C) exposes your data — both break least privilege.
Related topics
AWS KMS · Shared Responsibility Model · Amazon EC2
Ready to pass your AWS exam?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
