AWS I: CLI, IAM, S3 & KMS: interview questions
The question you are most likely to get for each topic, a model answer, and what else comes up. From chapter 35 of the course.
How does AWS decide whether a request is allowed? Mid
Every action is a signed API call, so AWS first knows who (the principal, from the signature) and what (service:Action on a resource ARN). Evaluation starts from a default deny. Any explicit Deny in any applicable policy wins. The organization's SCPs must allow the action, then an identity-based or a resource-based policy must allow it (in the same account either is enough; across accounts both sides must allow it), and a permissions boundary and session policies, if present, must allow it too. The AccessDenied message names the policy type that decided, and aws iam simulate-principal-policy tests the decision without calling the service.
Also asked: What is the difference between an IAM user and an IAM role? · How would you find out why a request got AccessDenied? · How do you keep S3 buckets from becoming public?
What is the difference between an AWS account, a Region and an Availability Zone? Junior
An account is the hard boundary for security, billing and quotas: it has its own IAM and nothing crosses it unless a policy allows it. A Region is a geographic area with its own copy of most services, such as eu-central-1; resources live in one Region. An Availability Zone is one or more isolated data centres inside a Region, so spreading across zones survives a data-centre failure. IAM is global to the account, most other services, such as KMS, are regional, and S3 bucket names are global while each bucket lives in one Region.
Also asked: What is an ARN and what are its parts? · Why would a company use many AWS accounts instead of one? · Which AWS services are global, and which are regional?
Learn it: 35.1 AWS for Azure people: accounts, regions, ARNs and the API
How does the AWS CLI decide which credentials to use? Junior
It walks the credential chain and the first hit wins: --profile on the command line, then the environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN), then the profile from the config files (the one AWS_PROFILE names, or default) with its keys, role or SSO settings, then container and instance-role credentials. The Region is resolved separately the same way. aws configure list shows which source won, and aws sts get-caller-identity shows who that identity is.
Also asked: What is the difference between the config and the credentials file? · How do you use several AWS accounts from one laptop? · Why is IAM Identity Center better than access keys for people?
Learn it: 35.2 The AWS CLI v2: install, configure, profiles and the credential chain
How do you get one value out of the AWS CLI into a shell variable? Junior
Select the field with JMESPath in --query and print it without quotes or JSON with --output text, for example ARN=$(aws iam get-role --role-name app --query Role.Arn --output text). The query runs on the client after the CLI has fetched every page, so for big lists add the operation's own server-side filter (such as --prefix) too. Check the exit code: 254 means AWS answered with an error, 252 that the command line itself was wrong.
Also asked: What is the difference between --query and a server-side filter? · How does pagination work in the AWS CLI? · How do you make AWS CLI commands safe to use in scripts?
Learn it: 35.5 Output, --query, pagination and reading errors
What is the difference between a managed and an inline policy? Junior
A managed policy is a standalone object with its own ARN and up to five versions, one of them the default, that you attach to many users, groups or roles; AWS managed policies such as ReadOnlyAccess are maintained by AWS, customer managed ones by you. An inline policy is embedded in one user, group or role and deleted with it. Use managed policies for reuse, review and rollback, and inline only for a permission that must stay with exactly one principal.
Also asked: What is the difference between an IAM user and an IAM role? · What are the elements of an IAM policy statement? · What is an identity-based policy versus a resource-based policy?
Learn it: 35.8 IAM: principals, groups, policies and the policy language
Walk me through how AWS evaluates a request. Mid
Default deny. AWS collects every applicable policy, and any explicit Deny wins immediately. Then the organization's SCPs must allow the action, then an identity-based or resource-based policy must allow it: in the same account either is enough, across accounts both sides must allow it. If the principal has a permissions boundary or the session has session policies, they must allow it too. The AccessDenied message names the policy type that decided ("because no identity-based policy allows" or "with an explicit deny in a service control policy"), and aws iam simulate-principal-policy tests the decision without calling the service.
Also asked: What is the difference between a permissions boundary and an SCP? · How does cross-account access differ from same-account access? · How do you debug an AccessDenied in AWS?
Learn it: 35.10 Policy evaluation: how AWS decides, and reading AccessDenied
What is a trust policy, and how do you give a CI pipeline AWS access without long-lived keys? Mid
A trust policy is the resource policy on a role that says which principals may assume it. For CI, register the CI system's OIDC provider in IAM and write a trust policy that allows sts:AssumeRoleWithWebIdentity only when the token's audience and subject match, for GitHub Actions aud = sts.amazonaws.com and sub = repo:org/repo:ref:refs/heads/main. The job exchanges its short-lived OIDC token for temporary role credentials (an ASIA key and a session token) that expire by themselves. No secret is stored anywhere, and the role's permissions policy limits what the pipeline can do.
Also asked: What is the difference between a role and a user? · What does sts:AssumeRole return? · What is role chaining, and what limit applies?
Learn it: 35.14 Roles and STS: trust policies, assume-role and temporary credentials
A developer pushed an access key to a public repository. What do you do? Mid
Contain first: deactivate the key at once with aws iam update-access-key --status Inactive, as a different principal. Identify the owner and last use with get-access-key-last-used. Investigate with CloudTrail lookup-events by AccessKeyId in us-east-1 (IAM, STS) and in every Region used: new users, keys, roles, instances, policy changes, and the source IP. Remove what the attacker created, issue a replacement (ideally a role or OIDC instead of a key), delete the leaked key and only then detach the AWSCompromisedKeyQuarantineV3 policy. Removing the commit is not enough; the key is burned.
Also asked: How do you rotate an access key without downtime? · What does CloudTrail event history contain, and what not? · What is the credential report?
Is S3 a filesystem? Junior
No. S3 is an object store: a bucket holds objects under keys in a flat namespace. "Folders" are only prefixes shown with a delimiter such as /, there is no rename (a move is a copy plus a delete), no append and no partial update, so you always replace whole objects. Reads after writes and lists are strongly consistent. Bucket names are global, while the data lives in the bucket's Region. For moving data use aws s3 cp and aws s3 sync; for exact API control use aws s3api.
Also asked: What is the difference between aws s3 and aws s3api? · How do you share one object without making the bucket public? · What are S3 storage classes used for?
Learn it: 35.22 S3: buckets, keys, prefixes and the s3 commands
How do you make sure no S3 bucket in an account is public? Mid
Prevent it in layers: turn on Block Public Access at the account level with all four settings, keep Object Ownership on BucketOwnerEnforced so ACLs are disabled, and protect the account setting with an SCP that denies s3:PutAccountPublicAccessBlock. Detect with aws s3api get-bucket-policy-status and IAM Access Analyzer findings for buckets shared outside the account. When one is public, remove the wildcard statement from the bucket policy (or turn Block Public Access back on), check CloudTrail for who changed it, and share data with presigned URLs or CloudFront instead.
Also asked: What is the difference between a bucket policy and an ACL? · How do you serve a static website from S3 securely? · What does RestrictPublicBuckets do?
Learn it: 35.24 S3 security: Block Public Access, bucket policies and object ownership
Someone deleted objects from a bucket. Can you get them back? Junior
Only if versioning was enabled before the delete (or there is a backup or replication). With versioning, a normal delete adds a delete marker: aws s3api list-object-versions shows it, and deleting the marker by its version ID brings the previous version back; an overwrite is undone by copying the older version over the current one. A delete that names a version ID is permanent, which is why s3:DeleteObjectVersion should be tightly restricted and why Object Lock exists for backups. A lifecycle rule then expires noncurrent versions so the safety net does not grow forever.
Also asked: What are S3 lifecycle rules used for? · What is the difference between SSE-S3 and SSE-KMS? · What is a delete marker?
Learn it: 35.27 Versioning, lifecycle rules and encryption at rest
What is envelope encryption, and why does KMS use it? Mid
KMS generates a data key and returns it twice: in plaintext and encrypted under the KMS key (aws kms generate-data-key). You encrypt the data locally with the plaintext data key, discard it, and store the encrypted data key next to the data. To read, KMS decrypts only the small data key. The master key never leaves KMS, KMS only handles up to 4 KB per call, large data never travels to KMS, and every kms:Decrypt is authorised by the key policy and logged in CloudTrail. S3 with SSE-KMS does exactly this for every object.
Also asked: Why can a role read a bucket but not download its objects? · What is a KMS key policy, and how does it relate to IAM policies? · What happens when you disable a KMS key?
Learn it: 35.29 KMS: keys, key policies, grants and the kms:Decrypt gotcha
How would you reduce the permissions of a service that has PowerUserAccess? Mid
Find what it really uses: service last accessed data (aws iam generate-service-last-accessed-details), CloudTrail events, or IAM Access Analyzer policy generation. Write a policy for exactly those actions on those resources (S3 prefixes, the queue ARN). Test it with aws iam simulate-custom-policy against the calls the service makes, attach the new policy first, then detach PowerUserAccess, run the workload, and watch for AccessDenied through a full cycle of its jobs, keeping the old policy for a rollback.
Also asked: How do you find every principal with admin rights in an account? · What do you look for in the IAM credential report? · What is ABAC, and when would you use it?
Practise these answers with flashcards and labs Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.