[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:devops-cloud\u002Faws-iam-security":4,"config":256},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":151,"samples":171},"devops-cloud","DevOps \u002F Cloud","","aws-iam-security","Aws Iam Security","en",75,3375,[14,15,16],"junior","mid","senior",[18,21,24,25,28,31,34,37,40,43,46,49,52,55,58,61,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127,130,133,136,139,142,145,148],{"key":19,"name":20,"count":11},"aws-compute-ec2-lambda","Aws Compute Ec2 Lambda",{"key":22,"name":23,"count":11},"aws-databases-rds-dynamodb","Aws Databases Rds Dynamodb",{"key":8,"name":9,"count":11},{"key":26,"name":27,"count":11},"aws-messaging-eventing","Aws Messaging Eventing",{"key":29,"name":30,"count":11},"aws-networking-vpc","Aws Networking Vpc",{"key":32,"name":33,"count":11},"aws-storage-s3-ebs","Aws Storage S3 Ebs",{"key":35,"name":36,"count":11},"azure-compute-vm-appservice","Azure Compute Vm Appservice",{"key":38,"name":39,"count":11},"azure-databases-sql-cosmosdb","Azure Databases Sql Cosmosdb",{"key":41,"name":42,"count":11},"azure-iam-security","Azure Iam Security",{"key":44,"name":45,"count":11},"azure-messaging-eventing","Azure Messaging Eventing",{"key":47,"name":48,"count":11},"azure-networking-vnet","Azure Networking Vnet",{"key":50,"name":51,"count":11},"azure-storage-blob-managed-disk","Azure Storage Blob Managed Disk",{"key":53,"name":54,"count":11},"ci-cd-pipelines","Ci Cd Pipelines",{"key":56,"name":57,"count":11},"cloud-architecture-scaling","Cloud Architecture Scaling",{"key":59,"name":60,"count":11},"containers-orchestration","Containers Orchestration",{"key":62,"name":63,"count":11},"deployment-release-strategies","Deployment Release Strategies",{"key":65,"name":66,"count":11},"gcp-compute-gce-cloudrun","Gcp Compute Gce Cloudrun",{"key":68,"name":69,"count":11},"gcp-databases-cloudsql-spanner-firestore","Gcp Databases Cloudsql Spanner Firestore",{"key":71,"name":72,"count":11},"gcp-iam-security","Gcp Iam Security",{"key":74,"name":75,"count":11},"gcp-messaging-eventing","Gcp Messaging Eventing",{"key":77,"name":78,"count":11},"gcp-networking-vpc","Gcp Networking Vpc",{"key":80,"name":81,"count":11},"gcp-storage-gcs-persistent-disk","Gcp Storage Gcs Persistent Disk",{"key":83,"name":84,"count":11},"infrastructure-as-code","Infrastructure As Code",{"key":86,"name":87,"count":11},"k8s-config-secrets","K8s Config Secrets",{"key":89,"name":90,"count":11},"k8s-observability-troubleshooting","K8s Observability Troubleshooting",{"key":92,"name":93,"count":11},"k8s-scheduling-resources","K8s Scheduling Resources",{"key":95,"name":96,"count":11},"k8s-services-networking","K8s Services Networking",{"key":98,"name":99,"count":11},"k8s-storage","K8s Storage",{"key":101,"name":102,"count":11},"k8s-workloads","K8s Workloads",{"key":104,"name":105,"count":11},"linux-filesystem-permissions-links","Linux Filesystem Permissions Links",{"key":107,"name":108,"count":11},"linux-networking-tools-troubleshooting","Linux Networking Tools Troubleshooting",{"key":110,"name":111,"count":11},"linux-performance-monitoring-resource-limits","Linux Performance Monitoring Resource Limits",{"key":113,"name":114,"count":11},"linux-process-management-signals","Linux Process Management Signals",{"key":116,"name":117,"count":11},"linux-shell-scripting-ops-automation","Linux Shell Scripting Ops Automation",{"key":119,"name":120,"count":11},"linux-systemd-service-management","Linux Systemd Service Management",{"key":122,"name":123,"count":11},"networking-dns-loadbalancing","Networking Dns Loadbalancing",{"key":125,"name":126,"count":11},"observability-monitoring","Observability Monitoring",{"key":128,"name":129,"count":11},"reliability-incident-sre","Reliability Incident Sre",{"key":131,"name":132,"count":11},"security-iam-secrets","Security Iam Secrets",{"key":134,"name":135,"count":11},"terraform-hcl-language-expressions","Terraform Hcl Language Expressions",{"key":137,"name":138,"count":11},"terraform-modules-workspaces","Terraform Modules Workspaces",{"key":140,"name":141,"count":11},"terraform-plan-apply-drift-import","Terraform Plan Apply Drift Import",{"key":143,"name":144,"count":11},"terraform-providers-lifecycle-provisioners","Terraform Providers Lifecycle Provisioners",{"key":146,"name":147,"count":11},"terraform-state-backend-locking","Terraform State Backend Locking",{"key":149,"name":150,"count":11},"terraform-testing-policy-cicd","Terraform Testing Policy Cicd",[152,156,159,162,165,168],{"key":153,"name":154,"count":155},"aws","AWS",450,{"key":157,"name":158,"count":155},"azure","Azure",{"key":160,"name":161,"count":155},"gcp","GCP",{"key":163,"name":164,"count":155},"kubernetes","Kubernetes",{"key":166,"name":167,"count":155},"linux","Linux",{"key":169,"name":170,"count":155},"terraform","Terraform",[172,190,203,217,230,243],{"id":173,"topic":9,"difficulty":174,"body":175,"options":176,"correct_key":184,"explanation":189},"019f8a47-3a33-7673-a985-7f7da23bcb1d",1,"Which policy on an IAM role determines who is allowed to assume that role?",[177,180,183,186],{"key":178,"text":179},"a","The role's permissions boundary",{"key":181,"text":182},"b","Any identity policy attached to the caller, by itself",{"key":184,"text":185},"c","The role's trust policy",{"key":187,"text":188},"d","The account password policy","A role's trust policy is the resource-based policy that names the principals or services allowed to call an STS role-assumption operation for that role. The role's identity policies define what an assumed session may do after assumption; a permissions boundary caps permissions but does not establish trust.",{"id":191,"topic":9,"difficulty":174,"body":192,"options":193,"correct_key":184,"explanation":202},"019f8a47-3a33-7dd7-a9ed-0b7cc84b55b0","Which elements define what an identity-based IAM policy statement allows or denies?",[194,196,198,200],{"key":178,"text":195},"Region, account alias, service endpoint, and credential profile",{"key":181,"text":197},"User, Group, Role, Policy",{"key":184,"text":199},"Effect, Action, Resource, and optional Condition",{"key":187,"text":201},"Encrypt, Decrypt, Sign, Verify","An identity-based policy statement uses Effect, Action, and Resource, with an optional Condition. Principal is not used because the attached identity is already the principal; Principal is used in resource-based policies and role trust policies.",{"id":204,"topic":9,"difficulty":205,"body":206,"options":207,"correct_key":178,"explanation":216},"019f8a47-3a34-76d0-b478-3a76e7389fdf",2,"What is the recommended way to grant the same set of IAM permissions to 30 developers who need identical access?",[208,210,212,214],{"key":178,"text":209},"Use federation through IAM Identity Center and assign the developers a shared permission set for the account",{"key":181,"text":211},"Copy the same inline policy into each of the 30 individual IAM users",{"key":184,"text":213},"Share one IAM user's access keys among all 30 developers",{"key":187,"text":215},"Attach the policy directly to the AWS account root user and have every developer log in as that same root account","AWS recommends that human users access AWS through federation with temporary credentials; IAM Identity Center provides centralized account access and reusable permission sets for this purpose. Copying inline policies to 30 IAM users is difficult to maintain, sharing credentials destroys individual auditability, and daily root use is unsafe.",{"id":218,"topic":9,"difficulty":174,"body":219,"options":220,"correct_key":187,"explanation":229},"019f8a47-3a35-7173-a696-ea4c3b6e94f2","Which of these is the single most important security step for the AWS account's root user?",[221,223,225,227],{"key":178,"text":222},"Rotating the root user's password every 24 hours",{"key":181,"text":224},"Creating long-lived access keys for the root user so automation can use it",{"key":184,"text":226},"Attaching an `AdministratorAccess` managed policy directly to the root user",{"key":187,"text":228},"Enable MFA and avoid using the root user for daily work","AWS's guidance is to enable MFA on the root user, avoid creating root access keys, and use root only for the few account-level tasks that require it. Human users should normally access AWS through federation, preferably centralized with IAM Identity Center, and receive temporary role credentials with least-privilege permissions. Root already has full account access, so attaching AdministratorAccess is redundant and creating root access keys adds unnecessary risk.",{"id":231,"topic":9,"difficulty":205,"body":232,"options":233,"correct_key":178,"explanation":242},"019f8a47-3a35-79a7-8788-f8fd3ac59b3d","How is an IAM role attached to an EC2 instance so that applications can obtain its temporary credentials from the instance metadata service?",[234,236,238,240],{"key":178,"text":235},"Through an instance profile that contains the IAM role",{"key":181,"text":237},"By placing the role ARN in the instance's user-data script only",{"key":184,"text":239},"By attaching the role's trust policy directly to the network interface",{"key":187,"text":241},"By converting the role into an IAM user after the instance starts","EC2 associates a role with an instance through an instance profile. The EC2 metadata service can then provide temporary credentials for that role to SDKs on the instance. User data and network interfaces do not create this IAM association, and roles are not converted into users.",{"id":244,"topic":9,"difficulty":174,"body":245,"options":246,"correct_key":178,"explanation":255},"019f8a47-3a36-7047-b35a-4459cd373891","By default, when an IAM user has no policies attached at all, what happens when they try to call any AWS API?",[247,249,251,253],{"key":178,"text":248},"It is denied unless a policy explicitly allows it",{"key":181,"text":250},"The request succeeds with read-only access by default",{"key":184,"text":252},"The request succeeds because IAM defaults to allowing all actions until a Deny is added",{"key":187,"text":254},"The request is routed to the account root user's permissions automatically","IAM's foundational rule is default-deny: unless a policy explicitly allows an action, it is denied. There is no implicit read-only or full-access default (b, c are wrong), and permissions are never silently inherited from the root user (d is wrong) — every principal's access is defined by its own attached\u002Finline policies.",{"fields":257,"seniorities":429,"interview_shapes":430,"locales":435,"oauth":437,"question_count":440,"coach_enabled":441,"jd_match_enabled":441},[258,283,303,320,330,343,362,381,403,410,416,423],{"key":259,"name_tr":260,"name_en":260,"sort":174,"specializations":261},"backend","Backend",[262,265,268,271,274,277,280],{"key":263,"name":264,"field":259},"general","Genel",{"key":266,"name":267,"field":259},"go","Go",{"key":269,"name":270,"field":259},"python","Python",{"key":272,"name":273,"field":259},"java","Java",{"key":275,"name":276,"field":259},"csharp","C#\u002F.NET",{"key":278,"name":279,"field":259},"nodejs","Node.js",{"key":281,"name":282,"field":259},"php","PHP",{"key":284,"name_tr":285,"name_en":285,"sort":205,"specializations":286},"frontend","Frontend",[287,288,291,294,297,300],{"key":263,"name":264,"field":284},{"key":289,"name":290,"field":284},"javascript","JavaScript",{"key":292,"name":293,"field":284},"typescript","TypeScript",{"key":295,"name":296,"field":284},"react","React",{"key":298,"name":299,"field":284},"vue","Vue",{"key":301,"name":302,"field":284},"angular","Angular",{"key":304,"name_tr":305,"name_en":305,"sort":306,"specializations":307},"fullstack","Fullstack",3,[308,309,310,311,312,313,314,315,316,317,318,319],{"key":263,"name":264,"field":304},{"key":266,"name":267,"field":259},{"key":269,"name":270,"field":259},{"key":272,"name":273,"field":259},{"key":275,"name":276,"field":259},{"key":278,"name":279,"field":259},{"key":281,"name":282,"field":259},{"key":289,"name":290,"field":284},{"key":292,"name":293,"field":284},{"key":295,"name":296,"field":284},{"key":298,"name":299,"field":284},{"key":301,"name":302,"field":284},{"key":5,"name_tr":6,"name_en":6,"sort":321,"specializations":322},4,[323,324,325,326,327,328,329],{"key":263,"name":264,"field":5},{"key":153,"name":154,"field":5},{"key":160,"name":161,"field":5},{"key":157,"name":158,"field":5},{"key":163,"name":164,"field":5},{"key":169,"name":170,"field":5},{"key":166,"name":167,"field":5},{"key":331,"name_tr":332,"name_en":332,"sort":333,"specializations":334},"ai-engineer","AI Engineer",5,[335,336,337,340],{"key":263,"name":264,"field":331},{"key":269,"name":270,"field":331},{"key":338,"name":339,"field":331},"llm-rag","LLM\u002FRAG",{"key":341,"name":342,"field":331},"mlops","MLOps",{"key":344,"name_tr":345,"name_en":346,"sort":347,"specializations":348},"database","Veritabanı","Database",6,[349,350,353,356,359],{"key":263,"name":264,"field":344},{"key":351,"name":352,"field":344},"postgresql","PostgreSQL",{"key":354,"name":355,"field":344},"mysql","MySQL",{"key":357,"name":358,"field":344},"mongodb","MongoDB",{"key":360,"name":361,"field":344},"redis","Redis",{"key":363,"name_tr":364,"name_en":365,"sort":366,"specializations":367},"mobile","Mobil","Mobile",7,[368,369,372,375,378],{"key":263,"name":264,"field":363},{"key":370,"name":371,"field":363},"ios-swift","iOS (Swift)",{"key":373,"name":374,"field":363},"android-kotlin","Android (Kotlin)",{"key":376,"name":377,"field":363},"flutter","Flutter",{"key":379,"name":380,"field":363},"react-native","React Native",{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"security","Güvenlik","Security",8,[387,388,391,394,397,400],{"key":263,"name":264,"field":382},{"key":389,"name":390,"field":382},"appsec","AppSec",{"key":392,"name":393,"field":382},"offensive-pentest","Offensive \u002F Pentest",{"key":395,"name":396,"field":382},"cloud-security","Cloud Security",{"key":398,"name":399,"field":382},"devsecops","DevSecOps",{"key":401,"name":402,"field":382},"blue-team-incident","Blue Team \u002F Incident",{"key":404,"name_tr":405,"name_en":406,"sort":407,"specializations":408},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[409],{"key":263,"name":264,"field":404},{"key":411,"name_tr":412,"name_en":412,"sort":413,"specializations":414},"data-engineer","Data Engineer",10,[415],{"key":263,"name":264,"field":411},{"key":417,"name_tr":418,"name_en":419,"sort":420,"specializations":421},"game-dev","Oyun Geliştirme","Game Development",11,[422],{"key":263,"name":264,"field":417},{"key":424,"name_tr":425,"name_en":425,"sort":426,"specializations":427},"ml-engineer","ML Engineer",12,[428],{"key":263,"name":264,"field":424},[14,15,16],{"junior":431,"mid":433,"senior":434},{"questions":432,"median_sec":3},20,{"questions":432,"median_sec":3},{"questions":432,"median_sec":3},[436,10],"tr",[438,439],"google","github",21750,true]