Phase Verbs / Action Phrases
| Phrase | Meaning |
|---|---|
| generate (a report) | create an output file/document from AWS |
| audit (credentials/permissions) | review and verify security-related settings |
| reduce (permissions) | remove unnecessary access rights |
| grant (service permissions) | allow a user to access a service |
Technical Vocabulary
| Term | Definition |
|---|---|
| IAM Credentials Report | Account-level CSV report of all IAM users and the status of their credentials (passwords, access keys, MFA) |
| IAM Access Advisor | User-level tool showing which AWS services a user has been granted access to and when they last used each |
| Least privilege principle | Give users only the minimum permissions needed to do their job |
| Service permissions | What AWS services a user is allowed to call (as defined by their policies) |
Key Concepts
Two IAM Security Tools
| Tool | Scope | What It Shows |
|---|---|---|
| Credentials Report | Account-level | All users + status of password, access keys, MFA |
| Access Advisor | User-level | Service permissions granted + when last used |
IAM Credentials Report
- Generated from the IAM console → download as CSV
- Shows for every user: password enabled/rotated, access keys active/rotated, MFA enabled
- Useful for auditing who has credentials and whether they’re following security best practices
IAM Access Advisor
- Per-user view inside IAM
- Helps identify unused permissions → remove them to follow least privilege
- Shows: service name, granted permission, last access time
Why Use These Tools?
- Enforce least privilege: if a user hasn’t accessed S3 in 90 days, they probably don’t need S3 access
- Quickly spot users with no MFA, old access keys, or excessive permissions
Exam Tips
- Credentials Report = account-level audit tool
- Access Advisor = user-level audit tool
- Both support the principle of least privilege
- These are audit/monitoring tools — they don’t change permissions themselves