Skip to content
Tech Interview Prep home
Technical interview guide

Cloud IAM Policy Design

Writing least-privilege access policies for cloud resources, and avoiding the common over-permissioning failure modes.

Read
44 min
Practice MCQs
25
Interview QA
25
Edition
v4
Editorial status
Reviewed

Scope: AWS IAM, Google Cloud IAM, Azure RBAC/managed identity, and NIST SP 800-207 guidance current 2026-08-31.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Explain why an AWS request is denied despite an identity allow.

QA-2

Design least-privilege cloud access for an engineering team.

QA-3

Give a Kubernetes workload access to one cloud storage bucket.

QA-4

Design cross-account access for a multi-tenant SaaS vendor.

QA-5

Secure a CI/CD pipeline that deploys production infrastructure.

QA-6

Design break-glass access for a cloud control-plane outage.

QA-7

Delegate IAM role creation to an application platform team.

QA-8

Prevent accidental public or cross-organization data access.

QA-9

Create a portable IAM model for a multi-cloud service.

QA-10

Introduce just-in-time production administration.

QA-11

Create and maintain a custom cloud IAM role.

QA-12

Migrate applications away from long-lived cloud access keys.

QA-13

Detect and remediate permission drift.

QA-14

Design organization-wide IAM deny guardrails.

QA-15

Respond to compromise of a privileged cloud identity.

QA-16

Enforce separation of duties for production changes.

QA-17

Use attributes and conditions to scope cloud access.

QA-18

Decide between a stored secret and cloud IAM for service access.

QA-19

Restore service during an outage caused by an IAM policy change.

QA-20

Run a quarterly cloud access review.

QA-21

Troubleshoot a conditional IAM policy that behaves inconsistently.

QA-22

Test IAM policy as infrastructure code before production.

QA-23

Design IAM isolation for tenants in a shared cloud application.

QA-24

Deprovision a departing administrator with cloud access.

QA-25

Define observability and metrics for cloud IAM.