Courseiva

Cross-Account IAM Role Trust Policy Configuration

A company wants to allow users from an external AWS account to assume an IAM role in its account. What must be configured in both accounts?

Quick Answer

The correct answer is that both the trusting account's role trust policy and the external account's IAM policy to allow sts:AssumeRole must be configured. This is because cross-account IAM role access requires a two-sided permission model: the trusting account (the role owner) must explicitly define a trust policy that designates the external account as a trusted principal, while the external account must grant its users an IAM policy with the sts:AssumeRole action to actually invoke the role. On the AWS Certified Security Specialty SCS-C02 exam, this concept tests your understanding of the shared responsibility in cross-account access—a common trap is assuming only one side needs configuration, such as thinking the trust policy alone is sufficient. A reliable memory tip is to remember the "handshake" rule: the trusting account opens the door (trust policy), and the external account provides the key (sts:AssumeRole permission).

⚠ Common exam trap

The trap is assuming that a trust policy alone is sufficient for cross-account access, when in fact AWS requires permissions on both the trusting and the calling side — a classic two-sided authorization misconception.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Both the trusting account's role trust policy and the external account's IAM policy to allow sts:AssumeRole.

Cross-account role assumption requires a two-sided trust relationship. The trusting account (where the role lives) must have a trust policy that names the external account as a Principal and allows sts:AssumeRole. The external account must also grant its users or roles an IAM policy permitting sts:AssumeRole on the role ARN, otherwise the request is denied even if the trust policy allows it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An IAM password policy in both accounts.

    Why it's wrong here

    Password policies govern console sign-in credentials and have no bearing on cross-account role assumption, which uses temporary STS credentials. It is tempting because identity controls feel relevant to access, but the required pairing is a trust policy in the trusting account and sts:AssumeRole permission in the external account.

  • ✗

    Only the trusting account's role trust policy.

    Why it's wrong here

    The trusting account's role trust policy alone lets the role be assumed only if the external account's identity also grants sts:AssumeRole on that role ARN. It is tempting because the trust policy is the visible cross-account control, but both sides must permit the call for the assume-role request to succeed.

  • ✗

    Only the external account's IAM policy to allow sts:AssumeRole.

    Why it's wrong here

    An external account policy granting sts:AssumeRole fails without a matching trust policy on the target role naming that account as principal. It is tempting because the caller's permission appears sufficient, but the trusting account must also delegate trust before STS will issue credentials.

  • ✓

    Both the trusting account's role trust policy and the external account's IAM policy to allow sts:AssumeRole.

    Why this is correct

    Cross-account role assumption requires two grants: the trusting account's role trust policy must name the external principal, and the external account's IAM policy must permit that principal to call sts:AssumeRole. Both sides must allow it.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses cross-account IAM roles to allow a third-party vendor to access resources in the company's AWS account. The security team wants to ensure that the vendor can only access the specific S3 bucket named 'vendor-bucket'. What should the security team do?

hard
  • A.Create an IAM user for the vendor and attach a policy that allows access to 'vendor-bucket'.
  • ✓ B.In the trust policy of the role, specify the vendor's AWS account and attach a permissions policy that allows s3:* on 'vendor-bucket'. Also create a bucket policy that allows the role.
  • C.Use an SCP to deny access to all S3 buckets except 'vendor-bucket'.
  • D.Create a new AWS account for the vendor and use VPC peering.

Why B: The correct approach is to create a cross-account IAM role for the vendor. In the role's trust policy, specify the vendor's AWS account as the trusted entity. Attach a permissions policy to the role that grants access only to the specific S3 bucket 'vendor-bucket' (e.g., s3:GetObject, s3:PutObject). Additionally, create a bucket policy on 'vendor-bucket' that allows the role to access the bucket. This ensures the vendor can only assume the role and access the designated bucket.

Variation 2. A security engineer is designing a cross-account IAM role to allow users in Account A to access resources in Account B. The engineer wants to restrict access to only users who have authenticated with multi-factor authentication (MFA) in Account A. What condition key should the engineer use in the trust policy of the IAM role in Account B?

hard
  • A.aws:SourceIp
  • ✓ B.aws:MultiFactorAuthPresent
  • C.aws:RequestedRegion
  • D.aws:UserAgent

Why B: The aws:MultiFactorAuthPresent condition key evaluates to true when the principal authenticated with MFA, so it can be used in the trust policy of the cross-account role in Account B to require MFA. Combined with a condition like 'aws:MultiFactorAuthPresent': 'true', the role can only be assumed by users in Account A who presented an MFA token. This is the canonical way to enforce MFA on cross-account role assumption.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.