Courseiva

SCS-C02 · domain

Identity and Access Management

This domain covers how AWS evaluates every request: IAM users, groups, roles, and policies, plus resource-based policies, permission boundaries, SCPs, and identity federation. You must read policy JSON and predict the effective permission, including explicit denies, trust policies, and cross-account access. Expect scenario questions on least-privilege design and credential handling.

151 questions48 easy62 medium41 hard

Focused practice

Practice Identity and Access Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Identity and Access Management

Given a scenario, determine the effective permissions by combining identity policies, resource policies, boundaries, SCPs, and conditions, then choose the least-privilege option. The single most important thing: an explicit Deny always wins, and roles with temporary credentials beat embedded access keys.

Reading IAM identity-based and resource-based policy JSON to determine effective allow or deny

Distinguishing IAM roles and STS AssumeRole from long-term access keys for AWS service access

Applying permissions boundaries, SCPs, and session policies as permission guardrails

Using iam:ChangePassword, iam:GetUser, and MFA conditions for self-service and console access

Watch out for

Common Identity and Access Management exam traps

  • ▸Forgetting that an explicit Deny in any applicable policy overrides every Allow, including administrator access.
  • ▸Assuming a resource-based policy alone grants access without checking the identity's own permissions or account trust.
  • ▸Confusing permissions boundaries with SCPs: boundaries limit identities, SCPs limit accounts in Organizations.

Question index

All Identity and Access Management questions (151)

Click any question to see the full explanation, or start a practice session above.

1

Which IAM entity can be used to grant temporary access to AWS resources for users from a different AWS account?

Easy
2

A developer needs to allow an EC2 instance to access an S3 bucket. Which is the best practice for granting permissions?

Easy
3

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that no IAM user in any account can create new IAM users. Which approach should be used?

Medium
4

A company wants to allow an IAM user to manage only their own access keys. Which IAM policy should be attached to the user?

Medium
5

An administrator needs to grant an IAM user the ability to change their own password without allowing them to change other users' passwords. Which IAM action should be included in the policy?

Easy
6

A security engineer runs the IAM policy simulator with a custom policy. The output shows the above. Which statement is true about the policy?

Medium
7

Which FOUR are valid ways to restrict access to an S3 bucket using IAM policies? (Choose 4.)

Hard
8

A security engineer must ensure that cross-account access to an S3 bucket is restricted to only accounts that are part of a specific AWS organization. Which IAM policy condition key should be used in the bucket policy?

Hard
9

Which TWO statements are true about IAM roles? (Choose two.)

Medium
10

A financial services company runs a production AWS account. A security engineer must ensure that IAM users cannot disable AWS CloudTrail logging in any region. The engineer attaches a permissions boundary to every IAM user. Which permissions boundary policy statement BEST enforces this requirement?

Medium
11

A company has an S3 bucket with a bucket policy that grants access to an IAM role used by an application running on EC2. The application is unable to read objects from the bucket, even though the IAM role has the necessary permissions. What is the most likely cause?

Medium
12

A security engineer is configuring AWS IAM Identity Center (successor to AWS Single Sign-On) for a company that uses an external identity provider (IdP) supporting SAML 2.0. The company wants to assign users to AWS accounts based on their groups in the IdP. The engineer has already configured the IdP and the SAML trust. What is the next step to ensure that users can access the correct AWS accounts with the appropriate permissions?

Hard
13

Which TWO of the following are AWS best practices for managing access keys? (Choose 2.)

Easy
14

A security engineer is configuring a VPC endpoint for Amazon S3 and wants to ensure that only traffic from specific IAM roles can access the S3 bucket through the endpoint. Which policy element should the engineer use?

Hard
15

A company runs a critical application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application processes financial transactions and must store transaction logs in an Amazon S3 bucket. The security team requires that all API calls to AWS services are logged and that the logs are stored in a secure, tamper-proof manner. The team enables AWS CloudTrail to log management events and Amazon S3 server access logs for the S3 bucket. They also enable AWS Config to track resource changes. The compliance team wants to ensure that no one can disable CloudTrail logging or delete the CloudTrail log files. The security engineer proposes a solution using an SCP in AWS Organizations to deny actions that would disable CloudTrail or delete log files. However, the engineer is concerned that the SCP might be applied too broadly and affect legitimate administrative actions. The engineer wants to ensure that only the security team’s IAM role (SecurityAdminRole) can perform these restricted actions, while all other principals (including IAM users, roles, and the root user) are denied. The engineer creates an SCP that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and s3:DeleteObject on the CloudTrail S3 bucket. The SCP includes a condition that allows the action if the principal is SecurityAdminRole. However, after applying the SCP, the security team finds that even SecurityAdminRole is unable to stop CloudTrail logging. What is the most likely cause of this issue?

Hard
16

A company wants to grant an IAM user the ability to rotate their own access keys. What is the least privileged IAM policy that allows this?

Easy
17

An application running on an EC2 instance needs to access an S3 bucket. What is the most secure way to grant the EC2 instance the necessary permissions?

Easy
18

Which THREE are valid methods for authenticating to AWS APIs? (Choose THREE.)

Easy
19

Which THREE of the following are characteristics of IAM roles? (Choose 3.)

Hard
20

A security engineer is designing a system to allow an EC2 instance to write logs to an S3 bucket. Which TWO steps are required?

Medium
21

A solutions architect needs to design a system where an EC2 instance can write logs to CloudWatch Logs. Which IAM entity should be used to grant permissions to the EC2 instance?

Easy
22

A company has an S3 bucket policy that allows cross-account access for a specific IAM role in another account. The bucket policy includes a Principal element with the ARN of the role. However, users in the other account that assume the role are unable to access the bucket. Which of the following is the MOST likely cause?

Medium
23

A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. Which THREE steps should the company take?

Medium
24

A company has multiple AWS accounts and wants to centrally manage access using IAM Identity Center (AWS SSO). Which feature allows the company to define permissions once and reuse them across multiple accounts?

Medium
25

A company uses AWS Organizations with a service control policy (SCP) that denies all actions except those explicitly listed. A developer in a member account needs to launch an EC2 instance with an IAM role that grants access to an S3 bucket. The SCP currently allows ec2:RunInstances and s3:GetObject but denies iam:PassRole. What is the MOST likely effect?

Medium
26

An IAM user reports that they are unable to launch an EC2 instance in us-east-1. The IAM policy attached to the user allows ec2:RunInstances but with a condition that the instance type must be t2.micro. What could be the reason for the failure?

Easy
27

A company uses AWS SSO to manage access to multiple accounts. An employee leaves the company. What is the most efficient way to revoke all AWS access for that employee?

Hard
28

Which TWO actions can be used to restrict access to an S3 bucket to only requests that originate from a specific VPC?

Medium
29

Which TWO of the following are valid use cases for IAM permissions boundaries? (Choose TWO.)

Hard
30

An administrator needs to allow a Lambda function to write logs to CloudWatch Logs. What is the BEST way to grant these permissions?

Easy
31

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that no IAM user in any account can create or modify IAM roles. What is the MOST effective way to enforce this?

Hard
32

An IAM policy has the following statement: {"Effect":"Deny","Action":"*","Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"false"}}}. What does this policy achieve?

Hard
33

A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The security team creates an IAM policy that denies all actions unless MFA is present. However, users report they can still perform actions without MFA. What is the most likely reason for this?

Easy
34

A security engineer is designing a permissions boundary for an IAM user. Which TWO statements about permissions boundaries are correct?

Hard
35

A company wants to allow users from an external AWS account to assume an IAM role in its account. What must be configured in both accounts?

Medium
36

A security engineer discovers that an IAM policy allows 'iam:CreateUser' and 'iam:CreateAccessKey' for all users in the account. Which risk does this pose?

Medium
37

A developer needs to allow an EC2 instance to read from a DynamoDB table named 'Orders' in the same account. The security team requires that the permissions be granted using an instance profile. Which steps should be taken?

Medium
38

A company wants to allow its employees to authenticate to the AWS Management Console using their existing corporate credentials. Which AWS service should be used to integrate with the company's identity provider?

Medium
39

A company uses IAM roles for cross-account access. Developers in Account A need to assume a role in Account B. What must be true for the AssumeRole call to succeed?

Medium
40

A company requires that all access to its S3 buckets be logged for compliance. Which AWS service should be used to record API calls to S3?

Easy
41

A security engineer is investigating an IAM role that was used to access AWS resources from an external account. The role has a trust policy that allows the external account to assume it. Which of the following is a required step for the external account to use the role?

Medium
42

Which THREE of the following are best practices for managing IAM access keys? (Choose THREE.)

Medium
43

A company wants to allow an external auditor to assume a read-only role in their AWS account. The auditor's AWS account ID is 123456789012. Which trust policy should be attached to the role?

Easy
44

Which TWO are IAM best practices? (Choose two.)

Easy
45

A company wants to allow users from its corporate Active Directory to access AWS resources. The company has set up an IAM identity provider for SAML. What must be created in IAM to map users to permissions?

Medium
46

A security engineer notices that an IAM role has a trust policy allowing any AWS account to assume it. Which attack is this misconfiguration most likely to enable?

Medium
47

Which THREE are best practices for securing IAM in an AWS environment? (Choose THREE.)

Hard
48

A security engineer needs to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which condition must be configured?

Hard
49

A developer needs to grant an IAM user access to a specific S3 bucket only. Which IAM policy element should be used to restrict access to that bucket?

Easy
50

A company wants to allow its development team to have full access to Amazon S3 buckets that are tagged with 'Environment: Dev'. Which IAM policy element should be used to restrict access based on tags?

Easy
51

A company is using IAM roles to grant EC2 instances access to an S3 bucket. The security team wants to ensure that the instances can only access their own bucket. Which policy should be attached to the IAM role to enforce this?

Medium
52

A security engineer needs to allow an application running on an Amazon EC2 instance to access an Amazon S3 bucket. The application must not use long-term credentials. The engineer has created an IAM role with the necessary permissions and attached it to the instance profile. However, the application is still receiving access denied errors. Upon investigation, the engineer finds that the application is using the AWS SDK for Java and is explicitly setting credentials via environment variables. What is the MOST likely cause of the access denied errors?

Hard
53

A company has an S3 bucket that contains sensitive data. The security team wants to ensure that all access to the bucket is encrypted in transit. What is the most effective way to enforce this?

Medium
54

A developer needs to grant an EC2 instance read-only access to an S3 bucket. Which of the following is the most secure way to provide these permissions?

Easy
55

Refer to the exhibit. An IAM policy allows running EC2 instances. A developer tries to launch a t2.micro instance but receives an 'AccessDenied' error. What is the most likely reason?

Hard
56

A company wants to allow a Lambda function to read objects from an S3 bucket in the same account. What should be done?

Easy
57

An organization wants to enforce multi-factor authentication (MFA) for all IAM users who perform sensitive actions. Which condition key should be used in an IAM policy to require MFA?

Medium
58

Which TWO actions can be performed using AWS IAM? (Choose two.)

Medium
59

An organization wants to enforce multi-factor authentication (MFA) for all IAM users accessing the AWS Management Console. Which policy should be used?

Medium
60

A company uses AWS Organizations with SCPs. The SCP for the production OU denies all actions on DynamoDB. An IAM policy attached to a user in that OU allows dynamodb:PutItem. What is the effective access?

Hard
61

Which TWO of the following are valid ways to grant an IAM user permissions to access an S3 bucket? (Choose 2.)

Medium
62

An IAM policy attached to a user contains the above statements. The user attempts to download an object from 'example-bucket/confidential/report.pdf'. What is the result?

Easy
63

A developer is trying to use the AWS CLI to list objects in an S3 bucket but receives an AccessDenied error. The developer has an IAM user with a policy that allows s3:ListBucket on the bucket. What could be causing the error?

Easy
64

A company has an IAM policy that allows s3:GetObject on all buckets. However, a specific S3 bucket policy explicitly denies s3:GetObject to all principals. An IAM user with the IAM policy tries to read an object from that bucket. What is the result?

Hard
65

An organization has a production AWS account and a development AWS account. Developers need to access the production account from the development account using IAM roles. What is the MOST secure way to set this up?

Medium
66

An organization wants to use AWS Organizations to centrally manage permissions for multiple accounts. Which IAM feature is used to grant cross-account access within the organization?

Easy
67

An application running on an EC2 instance needs to read from an S3 bucket. What is the BEST practice for granting permissions to the EC2 instance?

Easy
68

Which IAM feature allows you to grant temporary, limited-privilege credentials for a specific role?

Easy
69

A developer needs to run an application on an EC2 instance that accesses an S3 bucket. What is the best practice for granting permissions?

Easy
70

A security engineer is reviewing an IAM policy that grants permissions to an IAM user. The policy includes the following statement: { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::example-bucket/*" }. The engineer wants to ensure that the user can only access objects in the bucket when the request originates from a specific VPC endpoint. Which additional element should the engineer add to the policy?

Easy
71

A company wants to allow users to assume a role in another AWS account to access a specific S3 bucket. What must be configured?

Easy
72

An administrator wants to audit all IAM actions in the account. Which AWS service should be used?

Medium
73

A security engineer is designing a permissions boundary for an IAM role used by an EC2 instance. The role must be able to read from an S3 bucket (my-bucket) and write to CloudWatch Logs. Which THREE conditions must be met for the role to have effective permissions? (Choose THREE.)

Hard
74

An IAM policy allows the iam:PassRole action for a specific role only when the role is passed to EC2. A developer tries to launch an EC2 instance with this role, but fails. What is the most likely missing permission?

Easy
75

A developer needs to allow a Lambda function to write logs to CloudWatch Logs. What is the MINIMUM IAM policy that should be attached to the Lambda execution role?

Easy
76

A security team needs to audit all changes to IAM resources in their AWS account. Which AWS service should they use?

Medium
77

A company uses AWS Organizations with SCPs to restrict services. An administrator creates an SCP that denies access to EC2. A developer in a member account tries to launch an EC2 instance but fails. What is the most likely reason?

Medium
78

Refer to the exhibit. An IAM policy is attached to a group. A user in the group accesses the S3 bucket from an IP address 203.0.113.5 using HTTPS. What will be the result?

Hard
79

Which TWO are valid ways to authenticate an IAM user?

Easy
80

Which TWO are best practices for managing IAM roles for EC2 instances?

Medium
81

A security engineer notices that a developer's IAM user has full administrator access. The engineer wants to implement the principle of least privilege for the developer. What is the best way to proceed?

Hard
82

A security engineer is designing a system to manage access to an S3 bucket containing confidential data. Which TWO actions should the engineer take to implement least privilege?

Medium
83

A company uses AWS IAM Identity Center (AWS SSO) to manage access. A user is assigned to a permission set that grants AdministratorAccess. However, when the user tries to access the AWS console, they receive an error that they are not authorized. What is a possible reason?

Medium
84

An IAM policy includes: { "Effect": "Allow", "Action": "iam:PassRole", "Resource": "arn:aws:iam::*:role/MyRole" }. What does this allow?

Hard
85

A company wants to grant temporary credentials to mobile app users to access their own data in an S3 bucket. Which AWS service should be used to achieve this securely?

Easy
86

An IAM policy includes the following statement: 'Effect': 'Allow', 'Action': 's3:GetObject', 'Resource': 'arn:aws:s3:::example-bucket/*', 'Condition': {'IpAddress': {'aws:SourceIp': '192.0.2.0/24'}}. Which TWO statements about this policy are correct?

Medium
87

An IAM policy includes the following statement: 'Effect': 'Deny', 'Action': 's3:*', 'Resource': '*', 'Condition': {'Bool': {'aws:SecureTransport': 'false'}}. What does this policy do?

Easy
88

A developer needs to grant an EC2 instance access to an S3 bucket. Which is the most secure way to provide credentials to the EC2 instance?

Medium
89

An IAM policy grants access to a DynamoDB table with a condition that the request must originate from a specific VPC endpoint. However, requests from an EC2 instance in that VPC are being denied. What is the most likely cause?

Medium
90

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that no IAM user can have an access key older than 90 days. What is the MOST efficient way to achieve this?

Medium
91

Which TWO of the following are best practices for managing IAM user credentials? (Choose TWO.)

Easy
92

A company wants to allow users from an external AWS account to assume a role in the company's account. What must be configured in the company's account?

Easy
93

A security team wants to grant a Lambda function access to read from a DynamoDB table in the same account. What is the most secure way to do this?

Hard
94

A security engineer is configuring an IAM role for a Lambda function that must access an Amazon RDS database. The engineer wants the Lambda function to retrieve database credentials from AWS Secrets Manager without hardcoding them. Which combination of IAM permissions and trust policy is required?

Hard
95

A company has a single AWS account with multiple IAM users. The administrator created an IAM policy that allows all users to launch EC2 instances, but only if they use a specific AMI ID (ami-12345678) and a specific instance type (t3.micro). The policy uses a condition that checks the EC2 instance type and AMI ID. However, a user is able to launch an EC2 instance with a different AMI ID and a larger instance type. The administrator reviews the policy and confirms that the condition is correctly written. What is the most likely reason that the policy is not working as expected?

Easy
96

A security engineer reviews the trust policy of an IAM role. Which accounts can assume this role?

Medium
97

A developer needs to grant an IAM user temporary access to an S3 bucket for 15 minutes. Which AWS service should be used to generate temporary credentials?

Easy
98

Which THREE AWS services can be used to authenticate users for accessing AWS resources?

Hard
99

A security team notices that an IAM user has permissions to launch EC2 instances but should not have access to certain instance types. Which IAM policy condition key should be used to restrict this?

Hard
100

An IAM policy allows a user to pass a specific role and launch EC2 instances. The user tries to launch an EC2 instance with the role 'ec2-full-access' but receives an error: 'You are not authorized to perform iam:PassRole'. What is the MOST likely cause?

Hard
101

Which THREE factors should be considered when designing IAM policies for cross-account access? (Choose three.)

Hard
102

A company needs to grant cross-account access to an S3 bucket in Account A to users in Account B. What is the recommended approach?

Easy
103

Which TWO services can be used to manage identity and access across multiple AWS accounts? (Choose TWO.)

Easy
104

A company uses IAM roles for EC2 instances to access S3. A security audit reveals that some instances have roles with overly permissive policies. What is the BEST practice to scope down permissions while maintaining functionality?

Medium
105

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all IAM users in the production account must use multi-factor authentication (MFA) to access the AWS Management Console. Which combination of actions should the security team take to enforce this requirement?

Medium
106

A security engineer is reviewing an AWS account and notices that multiple IAM users have full administrative access. The company policy requires that users have only the permissions necessary to perform their job. What is the MOST secure and efficient way to enforce this policy?

Medium
107

Refer to the exhibit. A security engineer runs the IAM Policy Simulator with the provided policy input. The result shows 'explicitDeny' for ec2:RunInstances even though the policy only contains an Allow. What is the most likely reason?

Hard
108

A developer needs to access AWS resources from a mobile app. Which AWS service allows the app to obtain temporary credentials for authenticated users?

Easy
109

An IAM user has the policy shown in the exhibit. The user tries to launch an m5.large instance in us-east-1, but gets an 'AccessDenied' error. Why does this happen?

Medium
110

A security engineer notices that an IAM role has a trust policy that allows 'sts:AssumeRole' from any AWS account. What is the security risk?

Hard
111

A company uses an IAM role to allow an EC2 instance to access an S3 bucket. The instance is launched in a VPC with a VPC endpoint for S3. The IAM role has a policy that grants s3:GetObject on the bucket. However, the application on the instance receives 'Access Denied' errors when trying to read objects. What is the MOST likely cause?

Medium
112

Drag and drop the steps to implement AWS KMS key rotation in the correct order.

Medium
113

A company hosts a web application on EC2 instances behind an Application Load Balancer. The application accesses an S3 bucket to store user uploads. The security team needs to ensure that the EC2 instances can access the S3 bucket without storing AWS credentials on the instances. What should the security team do?

Medium
114

A company wants to allow an IAM user to manage only their own password in the AWS Management Console. Which IAM policy action should be used?

Easy
115

A company wants to grant an IAM user the ability to manage (create and update) their own access keys. Which TWO IAM actions must be allowed in the policy?

Easy
116

A developer needs to grant an IAM user read-only access to an S3 bucket named 'my-bucket'. Which policy should be attached to the IAM user?

Easy
117

Which TWO are characteristics of an IAM role? (Choose 2.)

Medium
118

A company wants to allow an IAM user to list objects in an S3 bucket named 'my-bucket'. Which IAM policy statement grants the minimum required permissions?

Easy
119

An organization wants to enforce that all IAM users must use MFA to access the AWS API. Which TWO steps should be taken?

Hard
120

A security engineer notices that an IAM role allows 'iam:PassRole' to an EC2 instance. What security risk does this present?

Medium
121

An AWS Lambda function needs to read from a DynamoDB table. What is the best practice for granting the Lambda function the necessary permissions?

Easy
122

A security engineer needs to grant an IAM user in Account A (111111111111) access to an S3 bucket in Account B (222222222222). The bucket policy in Account B allows cross-account access from Account A. Which additional step is required?

Medium
123

A security engineer needs to grant a third-party vendor temporary access to an S3 bucket in the company's AWS account. The vendor has its own AWS account and will use its own IAM users. The engineer wants to avoid creating IAM users in the company's account and wants to audit all access. Which solution meets these requirements?

Hard
124

An IAM policy has the following statement: {"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket/*"}. A user with this policy tries to perform s3:ListBucket on 'my-bucket'. Will the request succeed?

Hard
125

A security engineer is troubleshooting an issue where an IAM user is unable to list objects in an S3 bucket even though the user has an IAM policy that allows s3:ListBucket. What is the MOST likely cause?

Medium
126

Refer to the exhibit. This IAM policy is attached to a user. The user attempts to assume the AdminRole without using MFA. What is the result?

Hard
127

An IAM user reports that they are unable to launch an EC2 instance in a specific VPC. The user has an IAM policy that allows ec2:RunInstances but does not grant permission for the subnet resource. The VPC has a network ACL that allows all inbound and outbound traffic. What is the most likely cause of the failure?

Hard
128

A security engineer notices that an IAM user has permissions to create new IAM users and attach policies. What is the most effective way to detect if this user created a backdoor user?

Hard
129

Which TWO are valid IAM identity-based policies? (Choose 2.)

Easy
130

A security engineer is troubleshooting an issue where an IAM policy allows access to S3 but the user is denied access to a specific bucket. The policy has the following statement: { "Effect": "Allow", "Action": "s3:*", "Resource": "*" } What is the most likely cause of the denial?

Hard
131

A developer wants to allow an IAM role to be assumed by an EC2 instance that is part of an Auto Scaling group. Which TWO AWS services or features are required? (Choose TWO.)

Easy
132

A company has a policy that requires all IAM users to use multi-factor authentication (MFA) to access the AWS Management Console. A user reports that they are unable to sign in even after configuring MFA. What is the most likely cause?

Hard
133

A company's security policy requires that all IAM users must use strong passwords. Which IAM feature should be used to enforce this requirement?

Easy
134

A company uses IAM roles for EC2 instances. An application running on an EC2 instance needs to read from an S3 bucket in another AWS account. What is the most secure way to grant access?

Medium
135

A security administrator is designing a cross-account access strategy. The administrator needs to allow users in Account A to assume an IAM role in Account B to access an S3 bucket. Which TWO of the following statements are true regarding this configuration?

Medium
136

A company uses cross-account IAM roles to allow a third-party vendor to access resources in the company's AWS account. The security team wants to ensure that the vendor can only access the specific S3 bucket named 'vendor-bucket'. What should the security team do?

Hard
137

Refer to the exhibit. An IAM policy allows s3:GetObject on an S3 bucket only when the object is encrypted with SSE-KMS. An IAM user with this policy attempts to download an object that is not encrypted. What will happen?

Medium
138

A security engineer is designing a CI/CD pipeline that deploys AWS infrastructure using AWS CloudFormation. The pipeline must assume an IAM role in each target account to create and update stacks. Which TWO steps are required to allow cross-account access for CloudFormation? (Choose TWO.)

Medium
139

A company wants to allow an IAM user to list only the objects in a specific S3 bucket named 'my-bucket'. Which IAM policy statement should be used?

Easy
140

Refer to the exhibit. A KMS key policy allows decryption only when the request comes through S3 in us-east-1. An application in account 111122223333 tries to decrypt an S3 object using the KMS key directly via the KMS API (not through S3). What will happen?

Medium
141

Refer to the exhibit. An IAM policy is attached to a group. An IAM user in that group attempts to stop an EC2 instance from IP address 198.51.100.10. What will happen?

Medium
142

A company uses AWS IAM Identity Center (SSO) for managing access to multiple AWS accounts. A user reports that they can log in to the SSO portal but cannot see any AWS accounts in their dashboard. What is the most likely cause?

Medium
143

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM user in any account can create access keys. Which policy type should be used to enforce this restriction across all accounts?

Medium
144

Refer to the exhibit. A security engineer runs the 'simulate-custom-policy' command to test a policy. The output shows 'explicitDeny' for ec2:RunInstances. What is the most likely reason?

Medium
145

A company has multiple AWS accounts and wants to allow a user in the production account to assume a role in the development account. The role in the development account has a trust policy that allows the production account to assume it. What additional configuration is required?

Hard
146

A company has a requirement to grant cross-account access to an S3 bucket named 'shared-data' in Account A (111111111111) to users in Account B (222222222222). The security team has set up a bucket policy in Account A that grants read-only access to the IAM role 'DataReader' in Account B. The bucket policy is as follows: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"AWS":"arn:aws:iam::222222222222:role/DataReader"},"Action":["s3:GetObject"],"Resource":"arn:aws:s3:::shared-data/*"}]}. A user in Account B assumes the 'DataReader' role, but when trying to read an object from the bucket, they receive an 'Access Denied' error. What is the MOST likely reason for this error?

Medium
147

Refer to the exhibit. An EC2 instance with an IAM role attached attempts to access an S3 bucket, but receives an 'AccessDenied' error. The role has an attached policy allowing s3:GetObject on the bucket. What is the most likely cause?

Medium
148

A company wants to allow its users to assume an IAM role in a different AWS account. What must the company configure to enable cross-account access?

Easy
149

A developer is creating an AWS Lambda function that needs to read items from a DynamoDB table. The function is deployed in a VPC with no internet access. What is the MOST secure way to grant the Lambda function access to DynamoDB?

Hard
150

A company has an S3 bucket with a bucket policy that grants access to an IAM role. The security team wants to restrict access to only requests that originate from the company's VPC. How can this be achieved?

Hard
151

A security administrator discovers that an IAM user has been deleted accidentally. What is the correct way to restore the user's access?

Medium

Frequently asked questions

What does the Identity and Access Management domain cover on the SCS-C02 exam?
Given a scenario, determine the effective permissions by combining identity policies, resource policies, boundaries, SCPs, and conditions, then choose the least-privilege option. The single most important thing: an explicit Deny always wins, and roles with temporary credentials beat embedded access keys.
How many questions are in this domain?
This page lists all 151 Identity and Access Management questions in the SCS-C02 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Identity and Access Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
aws-security-specialty AWS-SECURITY-SPECIALTY iam Practice Questions