20+ practice questions focused on Identity and Access Management — one of the most tested topics on the AWS Certified Security Specialty SCS-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Identity and Access Management PracticeAn IAM policy includes the following condition: "StringNotEquals": {"aws:SourceArn": "arn:aws:ec2:us-east-1:123456789012:instance/*"}. What is the effect of this condition when attached to an IAM role?
Explanation: The condition uses `StringNotEquals` with `aws:SourceArn`, meaning it denies access when the source ARN does NOT match the specified pattern. Since the condition is attached to a role's trust policy, it restricts which principals can assume the role. The correct effect is that requests not originating from an EC2 instance in account 123456789012 and region us-east-1 are denied.
An IAM user receives an 'AccessDenied' error when trying to list objects in an S3 bucket. The user has the following policy attached: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::example-bucket"}]}. What is the most likely reason?
Explanation: The IAM policy grants the s3:ListBucket action on the bucket, which should allow listing objects. However, an explicit deny in a bucket policy overrides any allow, including those from IAM policies. Since the user receives an 'AccessDenied' error, the most likely cause is that the bucket policy explicitly denies the s3:ListBucket action for this user, as explicit denies take precedence over all allows.
Which TWO are valid ways to authenticate to AWS for API calls? (Choose two.)
Explanation: IAM user access keys (option B) are a valid authentication method for programmatic API calls to AWS. They consist of an access key ID and a secret access key, which are used to sign requests using Signature Version 4 (SigV4). This is a standard, long-term credential for IAM users to interact with AWS services via CLI, SDK, or direct API calls.
Refer to the exhibit. A security engineer runs the command above. Which of the following is true about the role MyRole?
Explanation: The command `aws ec2 associate-iam-instance-profile --instance-id i-1234567890abcdef0 --iam-instance-profile Name=MyRole` attaches an IAM instance profile to an EC2 instance. An instance profile is a container for an IAM role that enables EC2 instances to assume that role and obtain temporary credentials via the EC2 metadata service. Therefore, the role MyRole can be assumed by EC2 instances when associated through an instance profile.
A company has a multi-account AWS Organization with three accounts: Management, Development, and Production. The Security team uses the Management account to manage IAM policies centrally. They have created a service control policy (SCP) named 'RestrictRootAccess' that denies all actions for the root user in all accounts. The SCP is attached to the root organizational unit. The Development account has an IAM role 'DevAdmin' with full administrator access via an IAM policy. The role's trust policy allows the Management account's 'SecurityAudit' role to assume it. A security engineer in the Management account assumes the 'SecurityAudit' role and then tries to assume the 'DevAdmin' role in the Development account. The assumption fails with an 'AccessDenied' error. What is the most likely cause?
Explanation: The error 'AccessDenied' occurs because the trust policy of the 'DevAdmin' role in the Development account does not explicitly grant the 'sts:AssumeRole' action to the 'SecurityAudit' role from the Management account. Even though the 'SecurityAudit' role has permission to call sts:AssumeRole via its IAM policy, the target role's trust policy acts as a resource-based policy that must allow the incoming principal. Without that allow, the assumption fails regardless of permissions in the source account.
+15 more Identity and Access Management questions available
Practice all Identity and Access Management questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Identity and Access Management. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Identity and Access Management questions on the SCS-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Identity and Access Management is tested as part of the AWS Certified Security Specialty SCS-C02 blueprint. Practicing with targeted Identity and Access Management questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SCS-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Identity and Access Management is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Identity and Access Management practice session with instant scoring and detailed explanations.
Start Identity and Access Management Practice →