SCS-C02 Identity and Access Management Practice Question
A security administrator discovers that an IAM user has been deleted accidentally. What is the correct way to restore the user's access?
⚠ Common exam trap
Candidates often assume AWS provides an 'undelete' or 'restore from backup' feature for IAM users, similar to features in other AWS services like S3 versioning or RDS snapshots, but IAM has no such recovery mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new IAM user with the same name and attach the same policies
IAM does not support undeletion or restoration of deleted users. When an IAM user is deleted, all associated credentials, permissions, and metadata are permanently removed. The only way to restore access is to create a new IAM user with the same name and manually reattach the same policies, groups, and tags, and then regenerate access keys and passwords as needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Contact AWS Support to undo the deletion
Why it's wrong here
Calling AWS Support cannot restore a deleted IAM user: the DeleteUser API permanently removes the user object, including its path, permissions boundary, group memberships, and all attached inline or managed policies, and AWS retains no recoverable copy of that principal. Support engineers have no internal mechanism to reverse this operation; they will only advise you to recreate the user manually.
- ✗
Use the AWS IAM console to undelete the user
Why it's wrong here
The IAM console provides no undelete or recycle-bin feature. Once a user is deleted via the console, CLI, or API, the user object is immediately gone from the account, and the console only lets you create a brand-new IAM user—it cannot reconstruct the original user object, its ARN-based unique ID, or any of its embedded credentials.
- ✗
Restore the user from a backup of IAM
Why it's wrong here
IAM has no native backup/restore capability; unlike services such as DynamoDB or S3, there is no API to snapshot a user or to roll back a user to a previous state. Even if you exported CloudFormation templates or AWS Config rules that describe the user, those are infrastructure-as-code definitions, not backups of the live user object, and applying them would still create a fresh user rather than restoring the deleted one.
- ✓
Create a new IAM user with the same name and attach the same policies
Why this is correct
The only viable recovery is to create a new IAM user with the same name and reattach the same managed or inline policies, group memberships, and permissions boundaries, because the deleted user object is permanently irrecoverable. Be aware that the new user receives a different internal unique ID and you must reset the console password and generate new access keys, since all prior credentials—including the old secret access key—were destroyed at deletion and cannot be recovered.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.