Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to provide temporary security credentials to users accessing AWS resources from a mobile app. Which AWS service should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Cognito Identity Pools (Federated Identities)

Amazon Cognito Identity Pools (Federated Identities) allow you to create unique identities for your users and federate them with identity providers. With an identity pool, you can obtain temporary, limited-privilege AWS credentials to access other AWS services. This is the correct service for providing temporary security credentials to users accessing AWS resources from a mobile app. Option A (AWS Signer) is for code signing, not temporary credentials. Option B (AWS Directory Service) is for managing Microsoft Active Directory, not for generating temporary credentials. Option D (AWS IAM roles for cross-account access) is for granting access between AWS accounts, not for mobile app users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Signer

    Why it's wrong here

    AWS Signer is a code-signing service, not an identity or credential broker. It ensures the integrity and provenance of binary artifacts by attaching a digital signature, so it has no mechanism to issue or exchange temporary AWS security credentials for application users. Selecting Signer for this use case confuses artifact trust with user authentication.

  • ✗

    AWS Directory Service

    Why it's wrong here

    AWS Directory Service provides managed Microsoft Active Directory domains for authentication to AWS applications, Windows workloads, and SSO within a corporate network. While it can act as an identity source if federated to AWS via IAM, it does not itself issue short-lived AWS credentials, and it is not designed for anonymous or social-login mobile app users. Directory Service solves a different problem than issuing session credentials to an app's end users.

  • ✓

    Amazon Cognito Identity Pools (Federated Identities)

    Why this is correct

    Amazon Cognito Identity Pools are built specifically to trade identity tokens from any public or custom identity provider for temporary, least-privilege AWS credentials. The service assigns an IAM role per authenticated or guest user, and returns credentials with a short expiration that map to permissions defined in that role. This makes them the standard choice for mobile and web apps that need direct AWS API access without embedding long-term keys on devices.

  • ✗

    AWS IAM roles for cross-account access

    Why it's wrong here

    IAM roles created for cross-account access are intended for AWS principals in one account to assume a role in another, often with an external ID and strict trust policy. They do not accommodate end users who lack an AWS identity, have never been provisioned in an AWS account, and need federated login via social or enterprise identity providers. Using such a role directly for a mobile app would require every user to be an AWS principal, which is unrealistic and why Cognito Identity Pools exist.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.