Domain 4 · Identity and access management
20% of the exam. Proving who is calling, then deciding exactly what that caller may do, for people, workloads and applications.
Domain 4 questions give you a principal (an engineer, a CI pipeline, a mobile user, a partner account) and a resource, then ask why access fails, why it succeeds when it shouldn't, or how to grant it with the least privilege. Most answers come down to which credential the caller holds and which policy in the evaluation chain decides the result.
| Task | What it's really asking | Pages |
|---|---|---|
| 4.1 Authentication | Where identities live, how they get short-lived credentials, and why sign-in or role assumption fails | Workforce identity, Temporary credentials, Application identity |
| 4.2 Authorization | Writing and reading policies, guardrails across accounts, ABAC and RBAC, and finding excess or broken access | Policy evaluation, Permissions boundaries and delegation, Organization policies, Least-privilege tooling |
Themes that repeat
- No long-term keys. People sign in through IAM Identity Center, workloads on AWS use roles, workloads outside AWS use IAM Roles Anywhere or OIDC federation. Access keys are the last resort.
- Explicit deny wins. Every "why is this denied" question starts with finding the deny, then the missing allow.
- Guardrails don't grant. SCPs, RCPs, permissions boundaries and session policies only cap permissions.
- Measure, then trim. Access Analyzer and last accessed data turn "least privilege" from a slogan into a diff.
Exam signal
When the question says "most secure" and one option uses temporary credentials while another stores an access key (in a file, a parameter, an environment variable), the temporary-credential option is almost always right.
Granting with a guardrail
Options that "add an SCP that allows s3:GetObject" to fix an AccessDenied are wrong. An SCP can remove the block, but something still has to grant the permission, usually an identity policy or a resource policy.
Network segmentation and analysis
North/south and east/west protection, isolated subnets, Transit Gateway route tables for segmentation, VPC Reachability Analyzer, Network Access Analyzer, Inspector network reachability findings, and VPC Flow Logs for troubleshooting.
Workforce identity and federation
IAM Identity Center with permission sets, external IdPs over SAML and SCIM, Active Directory options and trusts, direct SAML federation to IAM roles, ABAC from IdP attributes, and MFA for people.