Your question is Driving Least-Privilege Across AWS. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
Tell me about a time you had to drive least-privilege access changes in a complex cloud environment with multiple teams or tenants. How did you reduce access without breaking critical workflows, and how did you handle resistance from engineers or service owners?