How should permissions be assigned for users?
Users should be assigned to groups and permissions assigned to the group.
How should permissions be assigned to services?
Services should be assigned a Role and permissions assigned to the Role.
How could you audit your IAM accounts?
Use IAM Credential Reports to review all accounts. Use IAM Access Advisor to review a specific account.
What does an IAM Policy statement consist of?
Sid, Effect, Principal, Action, Resource, and Condition.