Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer needs to grant a third-party auditor read-only access to all resources in an AWS account for a limited time. The auditor should not be able to make any changes. Which AWS service should the engineer use to provide temporary credentials?

⚠ Common exam trap

The trap here is thinking that IAM Identity Center is the default for temporary access, but it is intended for workforce SSO and not for external third-party auditors who need direct AWS API access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Security Token Service (AWS STS) with AssumeRole

AWS STS AssumeRole is the correct choice because it allows the creation of temporary credentials with a defined expiration and specific permissions. The engineer can create a role with read-only policies and allow the auditor to assume it. This provides secure, time-limited access without distributing long-term credentials. Other options either provide long-term credentials or are not designed for this use case.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS IAM Identity Center (successor to AWS Single Sign-On)

    Why it's wrong here

    IAM Identity Center is designed for workforce identity and access management, providing SSO access to multiple accounts. While it can grant temporary credentials, it is more complex and intended for internal users, not external auditors. It does not specifically address the need for temporary read-only access for a third party.

  • ✗

    AWS Identity and Access Management (IAM) with long-term access keys

    Why it's wrong here

    IAM long-term access keys are permanent unless rotated or deleted. They do not expire automatically, which violates the requirement for temporary access. They also pose a security risk if compromised. Using long-term keys for a third-party auditor is not best practice.

  • ✗

    Amazon Cognito identity pools

    Why it's wrong here

    Cognito identity pools are used to provide temporary AWS credentials for application users, not for third-party auditors. They are integrated with identity providers for consumer-facing apps. Using Cognito for this scenario would be inappropriate and overly complex.

  • ✓

    AWS Security Token Service (AWS STS) with AssumeRole

    Why this is correct

    AWS STS AssumeRole provides temporary security credentials with a specified duration. The engineer can create an IAM role with read-only permissions and allow the auditor to assume it, granting time-limited access without long-term credentials. This meets the requirement for temporary, read-only access.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.