Courseiva

SCS-C02 Identity and Access Management Practice Question

A company wants to allow its users to assume an IAM role in a different AWS account. What must the company configure to enable cross-account access?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the target account, create an IAM role with a trust policy that allows the source account, and attach a permissions policy to that role. In the source account, allow users to call sts:AssumeRole.

Cross-account access requires creating an IAM role in the target account with a trust policy that specifies the source account as a trusted entity, and attaching a permissions policy that defines what actions the role can perform. The source account must then have a policy that allows its users to call sts:AssumeRole for that role. Option A is incorrect because S3 bucket policies are used for resource-based access, not for role assumption. Option C is incorrect because sharing access keys violates security best practices and does not provide the controlled, temporary access that IAM roles offer. Option D is incorrect because trust policies are attached to roles, not IAM groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In the source account, create an S3 bucket policy that allows access from the target account.

    Why it's wrong here

    An S3 bucket policy governs access to objects in that bucket, not the ability to assume a role in another account, so it cannot enable cross-account role assumption. Bucket policies are the right tool for granting cross-account access to specific S3 resources.

  • ✓

    In the target account, create an IAM role with a trust policy that allows the source account, and attach a permissions policy to that role. In the source account, allow users to call sts:AssumeRole.

    Why this is correct

    Cross-account access requires two sides: the target account's role trust policy naming the source account as principal, plus a permissions policy granting the needed actions. The source account must additionally let its users call sts:AssumeRole, otherwise the role cannot be assumed.

  • ✗

    In the target account, create an IAM user and share the access keys securely with the source account users.

    Why it's wrong here

    Sharing long-lived IAM user access keys across accounts violates the cross-account access model, which requires a trust policy on the target role plus sts:AssumeRole from the source principal. It tempts because IAM users with access keys do grant programmatic access within a single account.

  • ✗

    In the target account, attach a trust policy to an IAM group that allows the source account.

    Why it's wrong here

    Trust policies attach to IAM roles, not groups, so a group-level trust policy cannot establish the cross-account assumption relationship. Groups are for bundling identities to receive permissions; the trust policy must sit on the role in the target account naming the source account as principal.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.