SCS-C02 Identity and Access Management Practice Question
A company wants to grant temporary credentials to mobile app users to access their own data in an S3 bucket. Which AWS service should be used to achieve this securely?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Cognito identity pools
Cognito Identity Pools can issue temporary AWS credentials for authenticated users. Option B is wrong because IAM users are not suitable for millions of mobile users. Option C is wrong because KMS is for encryption keys. Option D is wrong because CloudFront is a CDN, not for issuing credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon Cognito identity pools
Why this is correct
Amazon Cognito identity pools are purpose-built for granting temporary AWS credentials to mobile app users. When an identity is authenticated (via Cognito User Pools, social providers, or SAML), the identity pool exchanges the user's token for short-lived credentials by assuming an IAM role. These credentials are scoped to that role's permissions and automatically expire, eliminating the need to embed or manage long-term access keys. This is the standard serverless pattern for secure mobile access to AWS APIs.
- ✗
AWS Key Management Service (KMS)
Why it's wrong here
AWS Key Management Service (KMS) is a service for creating and controlling customer master keys used to encrypt and decrypt data. It does not issue, broker, or validate AWS credentials, and it provides no mechanism for authenticating an application user or generating temporary API keys. Using KMS in a mobile app would only help protect data at rest or in transit, not solve the problem of granting API access credentials. Confusing key management with credential management is a common misunderstanding, but KMS has no role in identity federation.
- ✗
IAM users with long-term access keys
Why it's wrong here
Creating IAM users with long-term access keys for mobile app users is insecure and unmanageable. The static key pair would be embedded in the app binary or stored on the device, where it can be extracted, tampered with, and reused indefinitely without per-user revocation. IAM users are intended for server-side workloads or service accounts, not for individual end users of an untrusted mobile client. Best practice is to use temporary credentials with limited scope and expiry, exactly what Cognito identity pools provide.
- ✗
Amazon CloudFront signed URLs
Why it's wrong here
Amazon CloudFront signed URLs are used to restrict access to content that CloudFront serves (e.g., media files or objects in S3) by adding a time-limited URL with an HMAC signature. They are a content-access control mechanism for HTTP requests, not a way to issue or obtain AWS API credentials. Even if your mobile app fetches content via signed URLs, those URLs cannot authenticate API calls to other AWS services. Thus signed URLs solve a different problem and do not grant the temporary AWS credentials the system requires.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.