Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to provide temporary, limited-privilege credentials to users so they can access AWS resources from mobile applications. Which AWS service should the company use?

⚠ Common exam trap

It's easy for candidates to confuse Amazon Cognito user pools (which handle authentication and user management) with identity pools (which use STS to grant AWS credentials), leading them to select Cognito user pools instead of STS as the direct service for temporary credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Security Token Service (STS)

AWS Security Token Service (STS) is the correct service because it enables the generation of temporary, limited-privilege credentials (access key, secret key, and session token) that can be used to access AWS resources. These credentials are ideal for mobile applications where long-term keys are a security risk, as they can be scoped with an IAM role and have a configurable expiration (default 1 hour, max 36 hours). STS supports the AWS Signature Version 4 signing process and can be called via the AssumeRole or GetFederationToken APIs to provide federated access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Security Token Service (STS)

    Why this is correct

    AWS Security Token Service (STS) is the correct service because it explicitly issues temporary, limited-privilege credentials—typically an access key ID, a secret access key, and a session token—with configurable durations (15 minutes to 12 hours). For a mobile app that needs scoped permissions without embedding permanent keys, STS operations like AssumeRole or GetFederationToken are the direct mechanism, and the returned credentials are automatically expired, reducing risk of long-term exposure.

  • ✗

    AWS Single Sign-On (SSO)

    Why it's wrong here

    AWS Single Sign-On (now IAM Identity Center) centralizes access across multiple AWS accounts and business applications via SAML or OIDC federation, but it is an authentication portal, not a direct issuer of temporary AWS credentials to a custom mobile app. While SSO integrates with STS to produce short-lived credentials after a user authenticates, the service itself does not hand out limited-privilege keys directly to endpoints; its role is identity and access management, so it is the wrong answer for this specific need.

  • ✗

    AWS Identity and Access Management (IAM) users

    Why it's wrong here

    IAM users are persistent identities that own long-term, static credentials such as access keys that never expire unless manually rotated. Because a mobile client would require embedding those permanent keys in the application or device—creating a significant security risk and lacking the 'temporary' attribute—IAM users fail the requirement. Even though an IAM user can assume a role to obtain temporary credentials, the user object itself is not a temporary credential service.

  • ✗

    Amazon Cognito user pools

    Why it's wrong here

    Amazon Cognito user pools provide authentication and user directory management, handling sign-up, sign-in, and token issuance (ID, access, refresh), but they do not directly issue AWS credentials. To receive temporary AWS credentials, an authenticated user would exchange a token from a user pool with a separate component—Cognito identity pools—which in turn calls STS. Thus, user pools alone cannot satisfy the stated need for temporary limited-privilege AWS credentials for a mobile app.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.