Cloud / AWS Management Console Interview questions
Last updated
1. What is the AWS Management Console?
The AWS Management Console is the browser-based interface for creating, configuring, and monitoring AWS resources. Instead of typing CLI commands or writing SDK code, you click through service consoles such as EC2, S3, and IAM.
It lives at console.aws.amazon.com and is also available as a mobile app. Behind every button the console calls the same service APIs the CLI uses, so your IAM permissions apply and each action shows up in CloudTrail.
It is great for learning, quick fixes, and visual dashboards. For repeatable deployments, most teams move to infrastructure as code.
Take quiz
a command-line tool installed on your laptop
a browser-based interface for managing AWS resources
a billing-only portal for invoices
a Java library for calling AWS services
handled by a separate permission system outside IAM
processed without any audit logging
sent to the same service APIs the CLI and SDKs use
limited to read-only operations
2. How do you sign in to the AWS Management Console?
You can sign in as the root user with the account email, or as an IAM user with the account ID (or alias), user name, and password. Workforce users in larger organizations normally sign in through IAM Identity Center or their corporate identity provider instead.
- Open the sign-in page or your account-specific URL, such as
https://<account-id-or-alias>.signin.aws.amazon.com/console. - Choose the user type (root or IAM user).
- Enter the credentials.
- Complete the MFA prompt if MFA is enabled.
- Pick a Region and open the service you need.
Access keys are not used for console sign-in. They are meant for the CLI, SDKs, and API calls.
Take quiz
only the root email address
the access key ID and secret access key
account ID or alias, user name, and password
the VPC ID and a subnet ID
one shared IAM user for the whole team
the root user for everyday work
access keys pasted into the sign-in page
IAM Identity Center or federation with an identity provider
3. What is the AWS account root user?
The root user is the identity created when you open an AWS account. You sign in with the email address used at sign-up, and it has complete, unrestricted access to every resource and to billing and account settings.
IAM policies cannot limit the root user of a standalone account, which is exactly why it is risky. In AWS Organizations, service control policies (SCPs) can restrict the root user of member accounts.
Best practice is to lock it down: a strong unique password, MFA, no access keys, and use only for the few tasks that truly require it.
Take quiz
can only view billing pages
is created by IAM when you add the first user
has permissions defined by the AdministratorAccess policy
is created with the account email and has unrestricted access
enable MFA and avoid creating access keys
share the password with all administrators
create access keys for automation scripts
turn MFA off to prevent lockout
4. What is an AWS account alias?
An account alias is a friendly name that replaces the 12-digit account ID in your IAM sign-in URL. With an alias of acme-prod, users sign in at https://acme-prod.signin.aws.amazon.com/console.
The alias must be globally unique across AWS and can contain lowercase letters, digits, and hyphens. An account can have only one alias at a time, and you create it from the IAM dashboard.
The original account-ID-based URL keeps working after you create an alias.
Take quiz
the 12-digit account ID
the Region name
the IAM user name
the service name
in the EC2 launch wizard
on the IAM dashboard
under Billing payment methods
in the CloudWatch alarms page
5. What is the Region selector in the AWS console?
The Region selector is the drop-down in the top navigation bar that decides which AWS Region the console talks to. Most services, including EC2, RDS, and Lambda, are regional, so you only see resources that exist in the selected Region.
The console remembers your last choice, and the Region also appears in the URL, for example us-west-2.console.aws.amazon.com. Picking the wrong Region is the most common reason people think a resource has disappeared.
Global services such as IAM show Global in place of a Region name.
Take quiz
EC2 instances are deleted after 24 hours
a different Region is currently selected
the console hides instances created by the root user
instances only appear in Global view
us-east-1 only
the Region nearest to your browser
Global
Disabled
6. What are global services in the AWS console?
Global services are not tied to a single Region, so their console pages show a Global label and ignore the Region selector. Examples are IAM, AWS Organizations, Route 53, CloudFront, and the Billing console.
Be careful with the exceptions. S3 shows one list of buckets, but each bucket lives in a specific Region. Many global services also keep their control plane in us-east-1.
| Global | Regional |
| IAM users, roles, policies | EC2 instances, EBS volumes |
| Route 53 hosted zones | RDS databases |
| CloudFront distributions | Lambda functions |
| AWS Organizations | VPCs and subnets |
Take quiz
Amazon EC2
AWS Lambda
IAM
Amazon RDS
exists in every Region at once
has no Region at all
is stored only in us-east-1
is created in a specific Region
7. What is the Console Home page?
Console Home is the landing page after sign-in. It is a dashboard of widgets that you can add, remove, and rearrange to fit your workflow.
Common widgets include Recently visited, Applications, Cost and usage, AWS Health, and Trusted Advisor. The Recently visited widget gets you back to your last-used services in one click, and the layout can be reset to default at any time.
Take quiz
restoring deleted resources
viewing CloudTrail logs
approving billing changes
jumping back to services you opened lately
added, removed, and rearranged
edited only by the root user
changed only through the CLI
viewed but never customized
8. How do you find a service quickly in the AWS console?
Use the search bar at the top of the console. Type a service name, feature, or even a task, and it returns matching services, features, documentation, and, if Resource Explorer is set up, resources.
The keyboard shortcut Alt+S (Option+S on Mac) jumps the cursor to the search box. You can also star services in the Services menu so they appear as favorites in the navigation bar.
Take quiz
adds it to your favorites for quick access
pins it to a specific Region permanently
grants you extra permissions on the service
disables billing alerts for it
Ctrl+Shift+Delete
Alt+S (Option+S on Mac)
F12
Alt+F4
9. What is the AWS Console Mobile Application?
The AWS Console Mobile Application is the official iOS and Android app for checking on your AWS environment while away from a desk. You can view resources, check CloudWatch alarms, see billing information, and perform limited operational actions on some services.
It supports sign-in with IAM user credentials, root credentials, or federated access, and can protect saved identities with device biometrics. It does not expose every service, so treat it as a monitoring companion rather than a full replacement for the web console.
Take quiz
building complete multi-tier architectures
monitoring resources and handling quick operational checks
running long CloudFormation deployments
replacing the CLI for scripting
by emailing yourself a recovery code
by disabling IAM for the account
with device biometrics such as fingerprint or face unlock
by using the root access key
10. What is AWS CloudShell?
AWS CloudShell is a browser-based shell you open directly from the console toolbar. It is already authenticated with the credentials you used to sign in, so you can run aws commands without configuring access keys.
The environment comes with the AWS CLI, Python, Node.js, git, and other common tools. It supports Bash, Zsh, and PowerShell, and you get 1 GB of persistent storage in your home directory per Region at no extra charge.
Take quiz
with a hard-coded root access key
with a key pair stored on S3
with the credentials of your current console session
with a password typed on every command
100 MB
50 GB
unlimited storage
1 GB
11. What is the Billing and Cost Management console?
The Billing and Cost Management console is where you view bills and invoices, manage payment methods, and track what your usage is costing. It includes Cost Explorer, Budgets, Cost Allocation Tags, and Free Tier usage tracking.
You open it from the account menu in the top-right corner. By default only the root user can see it, and IAM users need billing access activated by the root user before they can.
Take quiz
Session Manager
Resource Explorer
AWS Config
Cost Explorer
the root user
every IAM user automatically
only users in the Administrators group
anyone with an access key
12. What is the AWS Health Dashboard?
The AWS Health Dashboard shows what is happening with AWS services and with your own resources. It has two views: Service health for public, Region-wide events and Your account health for events that affect the resources in your account.
Account health covers scheduled maintenance, instance retirements, certificate expirations, and issues needing action. Open it from the bell icon in the console header.
Take quiz
Your account health
Service health
Trusted Advisor summary
Cost anomalies
the Billing payment page
the Your account health view
the IAM credential report
the CloudShell terminal
13. What is the Tag Editor in AWS?
Tag Editor, part of Resource Groups & Tag Editor, lets you find resources across multiple Regions and services and then add, edit, or remove tags in bulk.
You search by Region, resource type, and optional tag filters, then select results and manage their tags together. It is handy for fixing missing cost-allocation tags without opening each service console, though not every resource type supports tagging.
Take quiz
creating IAM users in bulk
searching resources and managing their tags in bulk
launching EC2 instances from templates
encrypting S3 buckets
only one bucket
only the Region you are signed in to
multiple Regions and services
only the root user's resources
14. What are AWS Resource Groups?
A Resource Group is a collection of AWS resources that you treat as one unit. There are two kinds: tag-based groups, which gather every resource matching a tag query, and CloudFormation stack-based groups, which gather the resources in a stack.
Once grouped, you can view them together in the console and run Systems Manager actions against the whole group. For example, a group built from the tag Environment=Dev shows all dev resources in one place.
Take quiz
share the same IAM policy
live in the same data center rack
match a tag query you define
were created on the same day
Region-based and price-based
user-based and role-based
public and private
tag-based and CloudFormation stack-based
15. How do you enable MFA for an IAM user in the console?
Open the user in IAM and register an authenticator from the Security credentials tab. The user can also do this themselves from the account menu.
- Go to IAM > Users and select the user.
- Open Security credentials and choose Assign MFA device.
- Enter a device name and pick the type: passkey or security key, authenticator app, or hardware TOTP token.
- Follow the prompts, entering two consecutive codes for an app or token.
- Choose Add MFA and confirm the device is listed.
An IAM user can register up to eight MFA devices.
Take quiz
only SMS text messages
only email codes
only the root user's phone
passkey/security key, authenticator app, or hardware TOTP token
up to 8
exactly 1
up to 3
unlimited
16. How do you create an IAM user with console access?
In the IAM console choose Users > Create user. Tick Provide user access to the AWS Management Console and set up the sign-in details.
- Enter a user name.
- Choose an auto-generated or custom password and decide whether to require a change at next sign-in.
- Add the user to a group or attach policies.
- Add optional tags and review.
- Create the user and download or email the sign-in instructions.
AWS recommends IAM Identity Center for people, so create IAM users mainly for cases where it can't be used.
Take quiz
Provide user access to the AWS Management Console
Create access key only
Attach AdministratorAccess only
Enable S3 Transfer Acceleration
locks the user permanently
forces the user to choose a new password at first login
deletes the initial password after 1 hour
enables MFA automatically
17. How do you launch an EC2 instance from the console?
Check the Region first, then open EC2 > Instances > Launch instances.
- Name the instance and add tags.
- Choose an AMI such as Amazon Linux.
- Pick an instance type like
t3.micro. - Select or create a key pair, or skip it if you plan to use Session Manager.
- Configure network settings: VPC, subnet, and a security group.
- Set storage and review the summary.
- Choose Launch instance.
The new instance appears in the Instances list and goes from pending to running.
Take quiz
the AMI
the security group
the key pair
the instance name tag
IAM > Users > Launch
S3 > Buckets > Launch
EC2 > Instances > Launch instances
Billing > Launch
18. How do you create an S3 bucket in the console?
Open S3 > Buckets > Create bucket, enter a bucket name that is unique across all of AWS, and select a Region. The Region matters because the bucket stays there.
Review the defaults: Block Public Access is on, ACLs are disabled through the bucket owner enforced setting, and new objects are encrypted with SSE-S3. Optionally enable versioning and tags, then choose Create bucket.
Take quiz
only within your account's Region
only inside one VPC
across all AWS accounts globally
only among your own IAM users
public read ACL
static website hosting
MFA Delete
Block Public Access
19. What is the Service Quotas console?
Service Quotas is the console where you view the limits applied to your account for each AWS service and request increases when a quota is adjustable.
You can see both the default value and your applied value per Region. You can also create CloudWatch alarms that fire as usage approaches a quota, which helps avoid surprise failures, such as being unable to launch instances.
Take quiz
raise IAM password complexity
purchase Savings Plans
rotate access keys
view applied quotas and request increases
to be notified before usage reaches the limit
to lower your bill automatically
to disable the Region
to rotate encryption keys
20. What is AWS Trusted Advisor?
Trusted Advisor inspects your account and recommends improvements in areas like cost optimization, performance, security, fault tolerance, service limits, and operational excellence.
It is available in the console, and a limited set of core checks is included with Basic and Developer support. The complete set of checks requires a Business, Enterprise On-Ramp, or Enterprise support plan. A typical finding is an idle load balancer or a security group open to the world.
Take quiz
cost optimization
code compilation
DNS hosting
image rendering
Basic only
Business and higher
Developer only
none; all checks are free for everyone
21. How do you set an IAM password policy?
Go to IAM > Account settings > Password policy and choose Edit. The policy applies to all IAM users in the account, not to the root user.
- Minimum length (up to 128 characters)
- Require uppercase, lowercase, numbers, and symbols
- Password expiration from 1 to 1,095 days
- Prevent reuse of up to 24 previous passwords
- Allow users to change their own password
- Require administrator reset after expiry
Consider stronger MFA instead of aggressive expiry rules.
Take quiz
EC2 > Security groups
IAM > Account settings
Billing > Payment methods
CloudTrail > Trails
the root user
only IAM roles
IAM users in the account
only access keys
22. How do you find your AWS account ID?
Click your account name in the top-right corner of the console. The 12-digit account ID is shown in the menu, with a copy icon beside it.
It also appears on the IAM dashboard and the Account page. From the CLI, run aws sts get-caller-identity and read the Account field. The ID identifies the account but is not a secret.
Take quiz
8 digits
16 digits
12 digits
a 40-character hash
aws ec2 describe-account
aws s3 ls --account
aws iam delete-account-id
aws sts get-caller-identity
23. What is the AWS Support Center?
The Support Center is where you open and track cases with AWS Support. Account and billing cases are available to every customer.
Technical support cases need a Developer, Business, Enterprise On-Ramp, or Enterprise plan, and the plan also sets response times. The Support Center also links to Trusted Advisor and the Health Dashboard, so many issues can be checked before a case is opened.
Take quiz
technical support
architecture review
24/7 phone technical support
account and billing
open and track cases with AWS Support
delete IAM users
configure VPC routing
create AMIs
24. What is the AWS Organizations console used for?
Use AWS Organizations to manage multiple AWS accounts centrally. From the management account's console you can create or invite accounts, group them into organizational units (OUs), and attach service control policies (SCPs) that set permission guardrails.
It also provides consolidated billing, so one payer account is billed for all member accounts and volume discounts are shared. Several AWS services integrate with it for organization-wide setup.
Take quiz
the maximum permissions available to accounts
Region latency targets
S3 lifecycle rules
the instance type of each account
each account is billed separately in cash
one payer account is billed for all member accounts
billing is turned off for members
only the root user receives invoices
25. What are the ways to access AWS services?
AWS offers several access methods, and they all end in the same service APIs.
| Method | Typical use |
| Management Console | Interactive, visual work in a browser |
| AWS CLI / CloudShell | Scripting and quick commands |
| SDKs | Calling AWS from application code |
| REST / Query APIs | Direct signed HTTPS requests |
| IaC (CloudFormation, CDK, Terraform) | Repeatable, version-controlled deployments |
Take quiz
the mobile app
an AWS SDK
the Support Center
Tag Editor
manual clicking in the console
the Billing console
infrastructure as code
the Health Dashboard
26. What is the difference between the AWS Console, CLI, and SDK?
All three call the same AWS APIs. They differ in how you drive them and how repeatable the result is.
| Aspect | Console | CLI | SDK |
| Interface | Browser GUI | Terminal commands | Code library |
| Best for | Exploring and one-off tasks | Scripting and automation | Application logic |
| Repeatability | Low, manual clicks | High, scripted | High, versioned code |
| Learning curve | Gentle | Moderate | Steeper |
| Credentials | Sign-in session | Access keys or SSO profile | Credential provider chain |
A common path is to prototype in the console, then convert the working setup to CLI scripts or IaC.
Take quiz
the AWS CLI
an AWS SDK
the Management Console
CloudFormation
they all share one access key
they all run inside CloudShell only
they all bypass IAM
they all call AWS service APIs
27. Why should you avoid using the root user for daily tasks?
The root user has unrestricted access, and IAM policies cannot limit it in a standalone account. If those credentials leak, the attacker can change billing, delete every resource, and even close the account.
Daily work should use IAM Identity Center or IAM roles with least-privilege permissions, so a mistake or compromise stays contained. Separate identities also give clean audit trails, because CloudTrail shows who did what.
- Enable MFA on the root user and remove root access keys.
- Store the password and MFA device in a secured, shared-control location.
- Sign in as root only for tasks that require it.
Take quiz
it makes the console slower
it increases the monthly bill
it removes CloudTrail logging
a compromise gives unrestricted control of the account
IAM Identity Center users or IAM roles with limited permissions
a second root user
a shared access key
an anonymous guest login
28. Which tasks require AWS root user credentials?
A small set of account-level tasks can only be done as the root user. Examples include:
- Changing the account name, root email, or root password
- Closing the AWS account
- Changing or canceling an AWS Support plan
- Restoring IAM permissions when no one else can manage IAM
- Activating IAM access to the Billing console
- Editing or deleting an S3 bucket policy that blocks all principals
For organizations, centralized root access management lets the management account perform privileged root actions on member accounts without keeping root credentials for each one. This lets teams remove member-account root passwords entirely.
Take quiz
closing the AWS account
launching an EC2 instance
creating an S3 bucket
creating an IAM role
give the root user unlimited free credits
perform privileged root tasks on member accounts without their root credentials
skip MFA on all accounts
share one root password across accounts
29. What is the difference between IAM user and IAM Identity Center sign-in?
An IAM user lives inside a single account with its own long-lived password. IAM Identity Center gives workforce users one sign-in portal that reaches many accounts, using temporary credentials.
| Feature | IAM user | IAM Identity Center |
| Scope | One account | Many accounts via the access portal |
| Credentials | Long-lived password | Short-lived session credentials |
| Permissions | Policies on user or group | Permission sets assigned per account |
| Identity source | IAM only | Built-in directory, Active Directory, or external IdP |
For people, Identity Center is usually the better choice because it centralizes access and removes long-term credentials.
Take quiz
an IAM user
IAM Identity Center
the root user
a bucket policy
permanent access keys only
no credentials at all
temporary, short-lived credentials
the root password
30. How do you switch roles in the AWS console?
Switch role lets a signed-in identity temporarily assume an IAM role, often in another account, without signing out.
- Open the account menu in the top-right corner and choose Switch role.
- Enter the 12-digit account ID (or alias) and the role name.
- Optionally set a display name and color so you recognize the session.
- Choose Switch Role.
It only works if the role's trust policy trusts your identity and your own permissions allow sts:AssumeRole on that role. The session length is capped by the role's maximum session duration, and the console remembers recently used roles for quick switching.
Take quiz
an attached EC2 key pair
a public S3 bucket
a trust policy that allows your identity to assume it
a Route 53 hosted zone
iam:CreateUser
s3:PutObject
ec2:RunInstances
sts:AssumeRole
31. How does federated sign-in to the AWS console work?
Federation lets users sign in with their corporate identity and land in the console without having an IAM user. A broker, such as your identity provider, exchanges proof of identity for temporary AWS credentials and builds a sign-in URL.
- The user authenticates with the identity provider.
- The broker calls STS (for example
AssumeRoleorAssumeRoleWithSAML) to obtain temporary credentials. - The broker sends those credentials to the federation endpoint to request a sign-in token.
- The broker builds a console login URL containing the token.
- The user is redirected and arrives in the console with the assumed role's permissions.
sequenceDiagram participant U as User participant IdP as Identity Provider participant STS as AWS STS participant FE as Federation Endpoint participant C as AWS Console U->>IdP: Sign in IdP->>STS: AssumeRole / AssumeRoleWithSAML STS-->>IdP: Temporary credentials IdP->>FE: Request sign-in token FE-->>IdP: Sign-in token IdP-->>U: Redirect with login URL U->>C: Open console as the role
The sign-in token is short-lived, about 15 minutes, so the URL must be used promptly.
Take quiz
a permanent root password
a new account ID
an S3 pre-signed bucket
temporary security credentials
the sign-in token expires after about 15 minutes
the user's IAM password rotates each minute
the Region changes hourly
CloudTrail deletes the token
32. How does AWS CloudShell handle authentication and data persistence?
CloudShell reuses the credentials of the identity signed in to the console, so a federated user gets the same permissions inside the shell as in the browser. The identity also needs permission to use CloudShell itself, such as the AWSCloudShellFullAccess managed policy.
Only your home directory persists, with 1 GB per Region. Files stored elsewhere vanish when the session ends, and installed packages outside $HOME must be reinstalled.
- Sessions end after a period of inactivity, around 20 to 30 minutes.
- Persistent storage is removed after 120 days without use in a Region.
- Files can be uploaded and downloaded from the Actions menu.
Take quiz
the home directory
the /tmp folder
the whole root filesystem
installed system packages
a separate CloudShell-only password
the signed-in IAM identity
the Region's default role
an automatically created root key
33. How do you connect to an EC2 instance from the console?
The Instances page has a Connect button that offers several browser-based options, each with different prerequisites.
| Option | Needs | Notes |
| EC2 Instance Connect | Port 22 reachable, supported AMI | Browser SSH using a temporary key |
| Session Manager | SSM Agent and an instance profile | No inbound ports or key pair |
| SSH client | Key pair and open port 22 | Shows the exact ssh command |
| EC2 serial console | Supported Nitro instance, enabled for account | Troubleshooting boot and network issues |
For production, Session Manager is generally favored because it avoids opening SSH to the internet.
Take quiz
EC2 Instance Connect over the internet
Session Manager
plain SSH client access
RDP over port 3389
uploading S3 objects
editing IAM policies
troubleshooting boot and network problems
creating Route 53 records
34. How does Session Manager connect through the browser without SSH keys?
The SSM Agent on the instance opens an outbound HTTPS connection to Systems Manager, and your browser session is relayed through that channel. Nothing connects inbound to the instance, so no port 22 and no key pair are needed.
- SSM Agent installed and running (preinstalled on many Amazon-provided AMIs)
- An instance profile with
AmazonSSMManagedInstanceCore - Outbound 443 to the SSM, SSM Messages, and EC2 Messages endpoints, or matching VPC endpoints
- The user allowed to call
ssm:StartSession
Session activity can be logged to S3 or CloudWatch Logs, and StartSession shows up in CloudTrail, giving you a stronger audit trail than plain SSH.
Take quiz
an open inbound port 22
a public Elastic IP only
SSM Agent and an instance profile with SSM permissions
a hard-coded SSH private key
ec2:StartSSH
iam:PassConsole
s3:OpenShell
ssm:StartSession
35. How does EC2 Instance Connect work?
When you click Connect, EC2 Instance Connect pushes a one-time public key to the instance metadata. That key stays valid for only 60 seconds, and the instance's SSH daemon fetches it to authenticate your browser session.
The caller needs the ec2-instance-connect:SendSSHPublicKey permission, and the security group must allow port 22 from the EC2 Instance Connect service IP range for that Region. It is supported on Amazon Linux and Ubuntu AMIs.
For instances without public IPs, an EC2 Instance Connect Endpoint can provide access from the console without a bastion host.
Take quiz
24 hours
7 days
until the instance is stopped
60 seconds
reaching instances that have no public IP
encrypting EBS volumes
scaling Lambda concurrency
routing DNS queries
36. How do you enforce MFA for console users with an IAM policy?
Use a policy that denies everything except a few self-service actions unless the request was authenticated with MFA. The key is the condition aws:MultiFactorAuthPresent.
{ "Version": "2012-10-17", "Statement": [{ "Sid": "DenyAllExceptMfaSetupWithoutMFA", "Effect": "Deny", "NotAction": [ "iam:CreateVirtualMFADevice", "iam:EnableMFADevice", "iam:ListMFADevices", "iam:ListVirtualMFADevices", "iam:ResyncMFADevice", "iam:ChangePassword", "iam:GetUser", "sts:GetSessionToken" ], "Resource": "*", "Condition": { "BoolIfExists": { "aws:MultiFactorAuthPresent": "false" } } }] }
BoolIfExists matters: it also denies requests where the key is missing, such as long-term access keys. Attach the policy to a group so new users inherit it.
Take quiz
aws:MultiFactorAuthPresent
aws:SourceVpc
aws:RequestedRegion
aws:PrincipalTag
so the policy applies only to the root user
so requests missing the MFA key are also denied
so MFA codes never expire
so S3 requests are exempt
37. How do you troubleshoot missing resources in the AWS console?
When a resource seems to have vanished, it is usually hidden rather than deleted. Work through these checks in order:
- Confirm the Region selector matches where the resource was created.
- Check the account ID and role shown in the account menu, in case you switched roles.
- Clear filters, such as an Instance state filter that hides stopped instances.
- Verify your IAM permissions for the list or describe actions.
- Search across Regions with Tag Editor or Resource Explorer.
- Look in CloudTrail for a delete event if the resource is truly gone.
Wrong Region and wrong account together cover most cases.
Take quiz
the instance's AMI ID
the selected Region
the DNS TTL
the VPC peering status
CloudShell history
Cost Allocation Tags page
Tag Editor or Resource Explorer
the Service Quotas console
38. How do you troubleshoot an "not authorized" error in the AWS console?
The error message names the action and the resource ARN that was denied, which tells you what to fix. Some services return an encoded message that you can decode with aws sts decode-authorization-message, which requires sts:DecodeAuthorizationMessage permission.
Then check each layer that could block the call:
- Identity-based policies on your user, group, or role
- Permissions boundary on the identity
- Service control policies from AWS Organizations
- Session policies from a role or federated session
- Resource-based policies, such as an S3 bucket policy
- Any explicit Deny, which always wins
The IAM Policy Simulator helps test the combination before you edit anything.
Take quiz
aws iam explain-error
aws ec2 show-denied
aws sts decode-authorization-message
aws cloudtrail decode-user
the most recently created Allow
the Allow on the resource policy
the policy with the shortest name
an explicit Deny
39. How can you audit AWS console sign-ins and actions?
Use CloudTrail. Every console sign-in produces a ConsoleLogin event that records who signed in, from which IP, whether it succeeded, and whether MFA was used. Console actions are logged as ordinary API events, with a user agent that identifies the console.
The Event history view keeps 90 days of management events, and you can filter by event name or user name. For longer retention, create a trail that delivers logs to S3.
Add a CloudWatch metric filter and alarm on root user ConsoleLogin events so you are notified the moment root is used. If a sign-in event is missing, check us-east-1, since events from the default sign-in endpoint are recorded there.
Take quiz
CreateSession
StartConsole
SigninToken
ConsoleLogin
90 days
24 hours
7 days
forever, with no setup
40. How do you give IAM users access to billing information?
Access is controlled in two layers. First, the root user must turn on IAM user and role access to Billing information on the Account page. Without that setting, even administrators are blocked.
Second, attach an IAM policy that allows the billing actions needed, such as viewing invoices or using Cost Explorer. AWS provides fine-grained actions, so you can allow Cost Explorer (ce:*) without letting someone change payment methods.
Grant billing permissions to a finance group rather than individuals, and keep payment-method changes limited to a very small set of people.
Take quiz
the root user
any IAM user with S3 access
an EC2 instance profile
AWS Support automatically
they share the root password
the policy allows only the needed ce: actions
they use the management account's access key
billing access is set to public
41. What is the difference between Cost Explorer and AWS Budgets?
Cost Explorer is for analysis: it graphs past spend and forecasts future spend. AWS Budgets is for control: it watches spend or usage against a threshold you set and alerts you when it is crossed.
| Aspect | Cost Explorer | AWS Budgets |
| Purpose | Analyze and forecast costs | Set limits and get alerts |
| Time view | Historical and forecast | Current period against a target |
| Alerts | No threshold alerts | Email or SNS notifications |
| Actions | None | Can trigger budget actions, such as applying an IAM or SCP policy |
Teams usually use both: Cost Explorer to find a spike, Budgets to catch the next one.
Take quiz
Cost Explorer
AWS Budgets
Resource Groups
Service Quotas
block API calls over a limit
rotate encryption keys
analyze historical spend and forecast future costs
manage DNS records
42. How do you enable an opt-in Region in the AWS console?
Regions launched after March 20, 2019, plus a few older ones like Hong Kong and Cape Town, are disabled by default. You must opt in before resources can be created there.
- Sign in as root or as an IAM principal with
account:EnableRegionpermission. - Open the account menu and go to Account.
- Find the AWS Regions section.
- Select the Region and choose Enable.
Enabling can take several minutes to hours. During that time the Region cannot be used, and IAM data is replicated to it automatically.
Take quiz
they are enabled for every account automatically
they can only be used by the root user
they are disabled by default until you enable them
they require a separate AWS account
ec2:EnableRegion
iam:OpenRegion
s3:EnableRegion
account:EnableRegion
43. How does AWS Console Private Access work?
Console Private Access lets users reach the console from inside a VPC or from on-premises over private connectivity instead of the public internet. It uses AWS PrivateLink interface endpoints for the console and sign-in services.
The security benefit is control over which accounts can be signed in to from your network. You list the allowed account IDs, and sign-ins to any other account are blocked, which reduces the risk of employees moving company data into personal AWS accounts.
flowchart LR A["Corporate network"] --> B["VPN or Direct Connect"] B --> C["VPC interface endpoints"] C --> D["AWS Console and Sign-in"] C -.-> E["Allowed accounts only"]
Take quiz
Route 53 weighted records
S3 Transfer Acceleration
an internet gateway only
AWS PrivateLink interface endpoints
which AWS accounts users can sign in to from your network
the size of EBS volumes
the number of Lambda invocations
the Regions where AMIs exist
44. How does Console-to-Code help automate console actions?
Console-to-Code records what you do in the console and turns it into reusable code. You start a recording, perform the actions, stop it, and review the list of recorded API calls.
It then generates code in formats such as the AWS CLI, CloudFormation, and CDK, using generative AI to produce the output. Support started with EC2 and has been growing to more services.
Treat the result as a starting point. Review parameters, remove hard-coded IDs, and test it before using it in a pipeline.
Take quiz
CLI, CloudFormation, or CDK code from recorded console actions
a billing report
an IAM credential report
a VPC flow log
deploy it to production as-is
review and refine it before reuse
ignore parameters
delete the recording immediately
45. How can you use multiple AWS accounts simultaneously in one browser?
The console supports multi-session, which lets you stay signed in to up to five accounts or roles at once in the same browser. You enable it from the account menu, then add sessions from the same menu.
Each session keeps its own identity and Region, and you can tell them apart by the account details in the menu. Before this feature, people relied on separate browser profiles, private windows, or Firefox containers.
Take quiz
exactly one
up to five
up to 50
unlimited
a single shared access key
SMS verification
separate browser profiles or private windows
CloudTrail Lake
46. How do you review unused credentials in the IAM console?
Two IAM tools help you find stale credentials. The Credential report is a downloadable CSV listing every user with fields such as password_last_used, access_key_1_last_used_date, and mfa_active. It can be generated at most once every four hours.
Access Advisor, on each user and role, shows which services were last accessed so you can trim permissions that are never used. IAM Access Analyzer can also produce unused-access findings.
Remove or deactivate credentials that have not been used for 90 days or more.
Take quiz
the Billing dashboard
the Security group list
the Credential report
VPC Flow Logs
a list of EC2 prices
the CloudFront cache hit ratio
S3 object sizes
the services a user or role last accessed
47. How does AWS Resource Explorer improve console search?
AWS Resource Explorer indexes your resources so you can search them by name, tag, or type across Regions and services, without opening each console page.
You turn it on by creating indexes in the Regions you want, then designating one as an aggregator index so a single search returns results from all of them. Once configured, results show up in the console's unified search bar.
Unlike Tag Editor, which is aimed at managing tags, Resource Explorer is built for quickly finding resources, even ones you can't remember the Region for.
Take quiz
encrypts all search queries
blocks cross-Region traffic
creates new EC2 instances
lets one search return results from multiple Regions
in the console's unified search bar
only in CloudTrail logs
only in the Billing console
only in the mobile app
48. When should you use the console instead of the CLI or infrastructure as code?
Choose the console for exploration and one-off work: learning a new service, investigating an incident, viewing graphs, or doing tasks that need root. Choose CLI or IaC when the result must be repeatable, reviewed, and versioned.
| Situation | Better choice |
| Learning or prototyping a service | Console |
| Debugging with dashboards and logs | Console |
| Deploying the same stack to 5 accounts | IaC |
| Nightly automation | CLI or SDK |
| Change that needs peer review | IaC |
The danger of manual clicking is configuration drift, because changes live only in someone's memory. Console-to-Code or a CloudFormation import can capture them afterward.
Take quiz
investigating an incident with dashboards
deploying identical stacks to many accounts
running a nightly job
building a reviewed release pipeline
automatic deletion of IAM roles
configuration drift that is not tracked in code
slower API response times
mandatory root sign-in
49. What happens when you create a resource in the AWS console?
The console is a front end for service APIs. When you click Create, it signs an API request with your session credentials and sends it to the service, for example RunInstances for EC2.
The service asks IAM to evaluate the request against all applicable policies. If allowed, the resource is created and the call is recorded in CloudTrail. The console then keeps polling calls like DescribeInstances to update the status on your screen.
sequenceDiagram participant U as You participant C as Console participant S as Service API participant I as IAM participant T as CloudTrail U->>C: Click Launch instance C->>S: Signed RunInstances request S->>I: Evaluate policies I-->>S: Allow or Deny S-->>C: Resource created (pending) S->>T: Log the API call C->>S: Poll DescribeInstances S-->>U: Status shows running
A denied request fails at the policy step, which is why permission errors in the console match CLI errors exactly.
Take quiz
the browser cache
IAM policy evaluation
the Route 53 resolver
the CloudFront edge location
both use the root user
the console ignores IAM policies
both send requests through the same API authorization
the CLI wraps the console
50. How can you secure access to the AWS Management Console?
Layer several controls so that no single failure exposes the account.
| Control | What it does |
| MFA, preferably phishing-resistant passkeys | Stops password-only takeover |
| IAM Identity Center or federation | Removes long-lived passwords for people |
| Least-privilege roles | Limits damage from any one identity |
| Root user lockdown | MFA, no access keys, rare use |
| Password policy | Raises the floor for IAM user passwords |
| CloudTrail and alarms | Detects suspicious sign-ins quickly |
| SCPs | Blocks risky actions across accounts |
| Console Private Access | Restricts sign-in to approved accounts from your network |
| Short session durations | Shrinks the window of a stolen session |
Review access regularly with the Credential report and Access Analyzer, and remove what is unused.