A cloud security engineer is reviewing an AWS IAM policy that includes the following statement: 'Effect: Allow, Action: iam:*, Resource: *'. Which two security concerns does this configuration create? (Choose TWO.)
Granting iam:* on Resource:* lets the principal create users, attach policies and modify roles across the whole account, far beyond any legitimate task. This violates least privilege, the specific concern the wildcard action and resource combination creates.
Why this answer
Option A (Over-permissive IAM role) is correct because Action: iam:* with Resource: * grants every IAM action on every IAM resource, far exceeding what any single role should hold and violating least privilege. Option E (Privilege escalation risk) is correct because iam:* includes actions like iam:CreatePolicyVersion, iam:AttachUserPolicy, iam:PutRolePolicy, and iam:PassRole, which let an identity grant itself or others broader permissions and effectively escalate to administrator. Option B is wrong because S3 bucket exposure depends on S3 bucket policies, ACLs, or Block Public Access settings, not an IAM statement.
Option C is wrong because hardcoded credentials are a code/secret-management issue, not something created by an IAM policy statement. Option D is wrong because SSRF is an application-layer vulnerability, not a property of an IAM policy.