Applications need permissions just as people do, and AWS Identity and Access Management (IAM) provides them through roles. A role is an identity with permission policies but no long-term password or access keys; whoever is allowed to assume it gets temporary credentials from the AWS Security Token Service (STS). Giving your code a role, rather than embedding an IAM user's access keys, is the pattern the exam expects every time.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.