Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to allow a user to assume a role in another AWS account to access resources. Which AWS service should be used to create and manage the trust relationship between the accounts?

⚠ Common exam trap

A common mix-up: candidates confuse the mechanism for establishing trust (IAM role trust policy) with the mechanism for obtaining credentials (STS), leading them to select STS as the answer despite it being a downstream step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IAM roles with a trust policy that allows the external account.

IAM roles with a trust policy that explicitly allows the external AWS account to assume the role is the correct mechanism for establishing a cross-account trust relationship. The trust policy defines which principal (the external account) is allowed to assume the role, and the permissions policy attached to the role controls what actions the assumed role can perform. This is the foundational AWS service for delegating access across accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IAM roles with a trust policy that allows the external account.

    Why this is correct

    IAM roles are the native AWS mechanism for cross-account access: the role's trust policy explicitly names the external account (or its users/roles) as a principal, and the permission policy grants the specific actions the role can perform. When the external user assumes the role, AWS verifies that the trust policy allows the request and then issues temporary credentials scoped to the role's permissions, making this the correct and secure way to enable the cross-account assumption.

  • ✗

    AWS Security Token Service (STS) to generate tokens.

    Why it's wrong here

    AWS STS is the service that issues temporary credentials when a role is assumed, but it does not itself define who is allowed to assume which role. STS simply processes the AssumeRole API call and relies on the role's trust policy to authorize the request; without a properly configured trust policy, STS will deny the call. Therefore, STS is a supporting component of the solution, not the mechanism that grants cross-account access.

  • ✗

    IAM users in the source account with cross-account permissions.

    Why it's wrong here

    IAM users are entities that exist within a single account and are used to authenticate that account's own principals; they cannot be used to directly assume a role from another account. Cross-account role assumption requires a role in the target account with a trust policy that allows the external account's principals, and the source account must have a policy granting its users or roles permission to call sts:AssumeRole. Simply defining 'cross-account permissions' for an IAM user does not create the required trust relationship, and it also conflicts with the principle of not using long-term IAM users for cross-account access.

  • ✗

    AWS Organizations service control policies.

    Why it's wrong here

    AWS Organizations service control policies (SCPs) are account-level permission boundaries that restrict the maximum permissions for all IAM principals in an account, but they do not establish any cross-account trust or define who can assume a role. SCPs can only deny or allow actions within the organization's accounts, and they cannot authorize a user from one account to assume a role in another. Therefore, SCPs may limit what a role can do after it is assumed, but they are never the mechanism that enables the assumption itself.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.