Courseiva

SCS-C02 Identity and Access Management Practice Question

A security administrator discovers that an IAM user has been deleted accidentally. What is the correct way to restore the user's access?

⚠ Common exam trap

Candidates often assume AWS provides an 'undelete' or 'restore from backup' feature for IAM users, similar to features in other AWS services like S3 versioning or RDS snapshots, but IAM has no such recovery mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new IAM user with the same name and attach the same policies

IAM does not support undeletion or restoration of deleted users. When an IAM user is deleted, all associated credentials, permissions, and metadata are permanently removed. The only way to restore access is to create a new IAM user with the same name and manually reattach the same policies, groups, and tags, and then regenerate access keys and passwords as needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Contact AWS Support to undo the deletion

    Why it's wrong here

    Calling AWS Support cannot restore a deleted IAM user: the DeleteUser API permanently removes the user object, including its path, permissions boundary, group memberships, and all attached inline or managed policies, and AWS retains no recoverable copy of that principal. Support engineers have no internal mechanism to reverse this operation; they will only advise you to recreate the user manually.

  • ✗

    Use the AWS IAM console to undelete the user

    Why it's wrong here

    The IAM console provides no undelete or recycle-bin feature. Once a user is deleted via the console, CLI, or API, the user object is immediately gone from the account, and the console only lets you create a brand-new IAM user—it cannot reconstruct the original user object, its ARN-based unique ID, or any of its embedded credentials.

  • ✗

    Restore the user from a backup of IAM

    Why it's wrong here

    IAM has no native backup/restore capability; unlike services such as DynamoDB or S3, there is no API to snapshot a user or to roll back a user to a previous state. Even if you exported CloudFormation templates or AWS Config rules that describe the user, those are infrastructure-as-code definitions, not backups of the live user object, and applying them would still create a fresh user rather than restoring the deleted one.

  • ✓

    Create a new IAM user with the same name and attach the same policies

    Why this is correct

    The only viable recovery is to create a new IAM user with the same name and reattach the same managed or inline policies, group memberships, and permissions boundaries, because the deleted user object is permanently irrecoverable. Be aware that the new user receives a different internal unique ID and you must reset the console password and generate new access keys, since all prior credentials—including the old secret access key—were destroyed at deletion and cannot be recovered.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.