Identity and Access Management Core Concepts
Individual people or services that need AWS access
Collections of users with similar permissions
Temporary credentials for AWS services or external users
JSON documents defining permissions
Remember: IAM is global (not region-specific). When questions ask about cross-account access or temporary credentials, think IAM Roles. For programmatic access, always prefer roles over access keys when possible.