Courseiva

SCS-C02 Identity and Access Management Practice Question

A security engineer notices that an IAM role allows 'iam:PassRole' to an EC2 instance. What security risk does this present?

⚠ Common exam trap

The trap is thinking that 'iam:PassRole' directly allows modifying IAM policies or other actions, when it specifically enables passing roles to services, leading to potential privilege escalation if not properly restricted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The instance can launch new resources with a more privileged role.

The 'iam:PassRole' permission allows an entity to pass an IAM role to an AWS service, such as EC2. If an EC2 instance has this permission, it can launch new resources (like another EC2 instance or a Lambda function) and associate a more privileged role with that resource. This is a privilege escalation risk because the instance could effectively gain the permissions of the passed role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The instance can launch new resources with a more privileged role.

    Why this is correct

    The ability to pass a role (iam:PassRole) combined with permission to launch EC2 instances (ec2:RunInstances) lets the instance specify a different, more privileged IAM instance profile at launch. Because the PassRole permission is often granted broadly without restricting which roles can be passed, the current instance can create a new instance carrying permissions beyond its own, thereby escalating privileges within the account.

  • ✗

    The instance can modify IAM policies.

    Why it's wrong here

    Modifying an IAM policy requires separate permissions such as iam:CreatePolicy, iam:PutRolePolicy, or iam:AttachRolePolicy. iam:PassRole only authorizes an entity to pass a role to an AWS service or resource during creation, not to alter the role's trust policy or its permission policies. Observing PassRole in the instance's permissions does not imply any IAM write capability.

  • ✗

    The instance can stop CloudTrail logging.

    Why it's wrong here

    Stopping CloudTrail logging requires the cloudtrail:StopLogging permission on the specific trail, which is unrelated to PassRole. Although a CloudTrail trail typically delivers events to an S3 bucket using a service role, the PassRole permission granted to the instance does not give it authority to call StopLogging or disable that delivery mechanism. Thus PassRole cannot impact the log recording state of CloudTrail.

  • ✗

    The instance can decrypt data encrypted with KMS keys.

    Why it's wrong here

    Decrypting data with KMS keys requires kms:Decrypt permission on the customer master key, which is governed by the key's key policy, key grants, and the caller's IAM policy. The iam:PassRole permission merely allows attaching a role to an EC2 instance or other service and does not confer any KMS cryptographic action. Even if the instance can pass a role, that does not automatically grant kms:Decrypt to that instance or any role.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.