CLF-C02 Security and Compliance Practice Question
Which AWS IAM object should be used to grant permissions to an AWS service (like EC2 or Lambda) to access other AWS services on behalf of the application?
⚠ Common exam trap
Many exam-takers confuse IAM Policies with IAM Roles, thinking a policy alone can grant permissions to a service, but a policy is just a permission document and must be attached to an identity (like a Role) that the service can assume.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM Role
An IAM Role is the correct AWS identity to grant permissions to an AWS service (e.g., EC2, Lambda) because it provides temporary security credentials via AWS Security Token Service (STS). Unlike IAM Users, roles are designed to be assumed by trusted entities, including AWS services, enabling them to access other AWS resources on behalf of the application without long-lived access keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IAM User with access keys
Why it's wrong here
IAM users are intended for human operators or persistent programmatic access, and storing their permanent access keys on an EC2 instance or Lambda function is an anti-pattern. Long-term credentials can be discovered in code, logs, or disk snapshots, and anyone with access to the instance can steal them. This is why AWS recommends using IAM roles with temporary credentials for any service, reducing the impact of credential leakage.
- ✗
IAM Group
Why it's wrong here
IAM Groups are logical containers for aggregating IAM users, not identities that AWS services can assume. You cannot attach a group to an EC2 instance or Lambda function, because groups only propagate permissions to the users inside them. To grant an AWS service permissions, you must create a role and attach that role to the service, not a group.
- ✓
IAM Role
Why this is correct
An IAM Role is an identity that AWS services assume to receive short-term, limited-privilege credentials from AWS STS. For EC2, you assign an instance profile to the instance, which enables it to assume the role and access other services securely. Lambda uses an execution role defined at creation time. This eliminates the need for long-term access keys and is the secure, best-practice method for service-to-service access.
- ✗
IAM Policy
Why it's wrong here
An IAM Policy is a JSON document that enumerates allowed or denied actions, but it is purely a set of permissions, not a principal. A policy must be attached to an IAM user, group, or role to have any effect; attaching it directly to an EC2 instance or Lambda function is not supported. Even if a policy were attached to a service, the service would still have no identity to act under, so you must attach the policy to a role that the service can assume.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.