GregLab | Exam Prep

Security, Identity, and Compliance

AWS Identity and Access Management (IAM)

The AWS service for controlling who is authenticated and what actions identities can perform on AWS resources.

Key points

  • IAM users, groups, roles, and policies support access control within and across accounts.
  • Policies define permissions; least privilege grants only the actions and resources that are needed.
  • Roles provide temporary credentials and are preferred to distributing long-lived access keys.

Best-known use cases

  • Grant workload or human access to AWS resources.
  • Delegate cross-account access without sharing credentials.

What candidates often confuse it with

  • Authentication proves identity; authorization evaluates permissions.
  • IAM controls AWS resource access; IAM Identity Center centralizes workforce access across accounts and applications.
  • The root user is not an ordinary IAM user and should not be used for daily administration.

Key Cloud Practitioner takeaway

Use IAM policies and roles for least-privileged AWS access; protect the root user separately.

Related services

  • AWS IAM Identity Center
  • AWS Secrets Manager

Relevant exam tasks

  • D2.3

Learn more

Free AWS Certified Cloud Practitioner prep

Build focused CLF-C02 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Build a quiz

Exam Weights

Exam snapshot

CLF-C02 at a glance

Category
Foundational
Duration
90 minutes
Questions
65 total; 50 scored and 15 unidentified unscored
Formats
Multiple choice and multiple response
Scoring
100–1,000 scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: AWS documents 65 questions in 90 minutes: 50 scored and 15 unidentified unscored, using multiple-choice and multiple-response formats. This site's practice accuracy and readiness do not reproduce AWS's 100–1,000 scaled scoring or identify unscored items. Difficulty labels describe this site's foundational scenario complexity, not an AWS-published question rating.

Reference

CLF-C02 topics and reference map

Study links

CLF-C02 resources