Asterrr's Handbook

Domain 4 · Identity and access management

20% of the exam. Proving who is calling, then deciding exactly what that caller may do, for people, workloads and applications.

Domain 4 questions give you a principal (an engineer, a CI pipeline, a mobile user, a partner account) and a resource, then ask why access fails, why it succeeds when it shouldn't, or how to grant it with the least privilege. Most answers come down to which credential the caller holds and which policy in the evaluation chain decides the result.

TaskWhat it's really askingPages
4.1 AuthenticationWhere identities live, how they get short-lived credentials, and why sign-in or role assumption failsWorkforce identity, Temporary credentials, Application identity
4.2 AuthorizationWriting and reading policies, guardrails across accounts, ABAC and RBAC, and finding excess or broken accessPolicy evaluation, Permissions boundaries and delegation, Organization policies, Least-privilege tooling

Themes that repeat

  • No long-term keys. People sign in through IAM Identity Center, workloads on AWS use roles, workloads outside AWS use IAM Roles Anywhere or OIDC federation. Access keys are the last resort.
  • Explicit deny wins. Every "why is this denied" question starts with finding the deny, then the missing allow.
  • Guardrails don't grant. SCPs, RCPs, permissions boundaries and session policies only cap permissions.
  • Measure, then trim. Access Analyzer and last accessed data turn "least privilege" from a slogan into a diff.

Exam signal

When the question says "most secure" and one option uses temporary credentials while another stores an access key (in a file, a parameter, an environment variable), the temporary-credential option is almost always right.

Granting with a guardrail

Options that "add an SCP that allows s3:GetObject" to fix an AccessDenied are wrong. An SCP can remove the block, but something still has to grant the permission, usually an identity policy or a resource policy.

On this page