Courseiva
Security and Compliance →easyMultiple Choice

CLF-C02 Security and Compliance Practice Question

Which AWS IAM object should be used to grant permissions to an AWS service (like EC2 or Lambda) to access other AWS services on behalf of the application?

⚠ Common exam trap

Many exam-takers confuse IAM Policies with IAM Roles, thinking a policy alone can grant permissions to a service, but a policy is just a permission document and must be attached to an identity (like a Role) that the service can assume.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IAM Role

An IAM Role is the correct AWS identity to grant permissions to an AWS service (e.g., EC2, Lambda) because it provides temporary security credentials via AWS Security Token Service (STS). Unlike IAM Users, roles are designed to be assumed by trusted entities, including AWS services, enabling them to access other AWS resources on behalf of the application without long-lived access keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IAM User with access keys

    Why it's wrong here

    IAM users are intended for human operators or persistent programmatic access, and storing their permanent access keys on an EC2 instance or Lambda function is an anti-pattern. Long-term credentials can be discovered in code, logs, or disk snapshots, and anyone with access to the instance can steal them. This is why AWS recommends using IAM roles with temporary credentials for any service, reducing the impact of credential leakage.

  • ✗

    IAM Group

    Why it's wrong here

    IAM Groups are logical containers for aggregating IAM users, not identities that AWS services can assume. You cannot attach a group to an EC2 instance or Lambda function, because groups only propagate permissions to the users inside them. To grant an AWS service permissions, you must create a role and attach that role to the service, not a group.

  • ✓

    IAM Role

    Why this is correct

    An IAM Role is an identity that AWS services assume to receive short-term, limited-privilege credentials from AWS STS. For EC2, you assign an instance profile to the instance, which enables it to assume the role and access other services securely. Lambda uses an execution role defined at creation time. This eliminates the need for long-term access keys and is the secure, best-practice method for service-to-service access.

  • ✗

    IAM Policy

    Why it's wrong here

    An IAM Policy is a JSON document that enumerates allowed or denied actions, but it is purely a set of permissions, not a principal. A policy must be attached to an IAM user, group, or role to have any effect; attaching it directly to an EC2 instance or Lambda function is not supported. Even if a policy were attached to a service, the service would still have no identity to act under, so you must attach the policy to a role that the service can assume.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.