SCS-C02 Management and Security Governance Practice Question
A security engineer needs to grant a third-party auditor read-only access to specific AWS Config compliance data in a production account for 30 days. The auditor uses their own AWS account and must not be able to modify any resources or view unrelated data. The security engineer wants to avoid creating IAM users in the production account. Which approach BEST satisfies these requirements?
⚠ Common exam trap
The trap here is assuming AWS Config aggregators grant external parties direct read access, when they only consolidate data for the aggregator owner.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role in the production account with a trust policy allowing the auditor's account and attach a policy granting config:Describe* and config:Get* actions, then provide the role ARN to the auditor.
A cross-account IAM role with a trust policy scoped to the auditor's account and permissions limited to AWS Config read actions provides temporary, least-privilege access without creating local IAM users. The auditor assumes the role using their own credentials. Aggregators, service-linked role modifications, and local IAM users either fail to grant the needed access, broaden exposure, or violate the no-local-user constraint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an IAM role in the production account with a trust policy allowing the auditor's account and attach a policy granting config:Describe* and config:Get* actions, then provide the role ARN to the auditor.
Why this is correct
Cross-account IAM roles allow the auditor to assume a role in the production account without creating local IAM users. Attaching only Config read actions enforces least privilege, and the trust policy scopes access to the auditor's account. This meets the no-local-users requirement while limiting permissions to compliance data retrieval only, which is exactly what the scenario asks for.
- ✗
Attach a resource-based policy to the production account's AWS Config service-linked role permitting the auditor's account principal to call config:GetComplianceDetailsByConfigRule.
Why it's wrong here
AWS Config does not support resource-based policies on its service-linked role, and service-linked roles cannot be modified to trust external accounts. This approach is technically invalid. The auditor needs a cross-account IAM role with a trust policy, not a modification to a service-linked role, so the solution cannot be implemented as described.
- ✗
Create an IAM user in the production account for the auditor with a read-only managed policy and enable MFA, sharing credentials securely for the 30-day period.
Why it's wrong here
Creating IAM users in the production account directly contradicts the requirement to avoid local users. Long-lived credentials shared with an external party also increase risk and are hard to revoke cleanly. A read-only managed policy is broader than needed and could expose unrelated data, so this approach fails both the least-privilege and no-local-user requirements.
- ✗
Share the production account's AWS Config data by enabling an AWS Config aggregator in the auditor's account and authorizing the production account as a source account.
Why it's wrong here
A Config aggregator consolidates configuration and compliance data across accounts for the aggregator owner, but it does not grant the auditor interactive read access to the production account's Config API. It also requires the production account to authorize the aggregator, which broadens data exposure. This does not provide scoped, time-bound read access to specific compliance data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.