ANS-C01 Network Security, Compliance and Governance Practice Question
A company uses AWS Certificate Manager (ACM) to issue certificates for a fleet of Application Load Balancers. The security team requires that only specific IAM roles can request, renew, or delete ACM certificates. Which policy type should be used to enforce this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM identity-based policies attached to the IAM roles
ACM access is controlled via IAM identity-based policies attached to IAM roles, which allow specifying which roles can request, renew, or delete certificates. Option A is incorrect because AWS managed policies are a type of IAM policy, but the question asks for the policy type used to enforce access for specific IAM roles, and AWS managed policies can be used but are not the only type; however, the key point is that identity-based policies are the mechanism. Option B is incorrect because service control policies (SCPs) apply to all accounts in an AWS Organization and cannot target specific IAM roles within an account. Option D is incorrect because ACM does not support resource-based policies; only IAM policies can be used to control access to certificates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS managed policies such as AWSCertificateManagerFullAccess
Why it's wrong here
Managed policies are a type of IAM policy, but the question asks for the policy type; B is more precise.
- ✗
Service control policies (SCPs) in AWS Organizations
Why it's wrong here
SCPs apply to all accounts, not specific roles.
- ✓
IAM identity-based policies attached to the IAM roles
Why this is correct
IAM policies control access to ACM actions.
- ✗
Resource-based policies attached to the ACM certificates
Why it's wrong here
ACM does not support resource-based policies.
Go deeper
Related to this question
About these practice questions
Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.