Exit 24 / 40

Question 24

Domain 4: Identity and Access Management

An AWS security architect is defining IAM permissions so that no single employee can both grant elevated access and use that access to make sensitive production changes. Which authorization design BEST enforces proper separation of duties?