SCS-C02 Identity and Access Management Practice Question
A security engineer notices that an IAM role allows 'iam:PassRole' to an EC2 instance. What security risk does this present?
⚠ Common exam trap
The trap is thinking that 'iam:PassRole' directly allows modifying IAM policies or other actions, when it specifically enables passing roles to services, leading to potential privilege escalation if not properly restricted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The instance can launch new resources with a more privileged role.
The 'iam:PassRole' permission allows an entity to pass an IAM role to an AWS service, such as EC2. If an EC2 instance has this permission, it can launch new resources (like another EC2 instance or a Lambda function) and associate a more privileged role with that resource. This is a privilege escalation risk because the instance could effectively gain the permissions of the passed role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The instance can launch new resources with a more privileged role.
Why this is correct
The ability to pass a role (iam:PassRole) combined with permission to launch EC2 instances (ec2:RunInstances) lets the instance specify a different, more privileged IAM instance profile at launch. Because the PassRole permission is often granted broadly without restricting which roles can be passed, the current instance can create a new instance carrying permissions beyond its own, thereby escalating privileges within the account.
- ✗
The instance can modify IAM policies.
Why it's wrong here
Modifying an IAM policy requires separate permissions such as iam:CreatePolicy, iam:PutRolePolicy, or iam:AttachRolePolicy. iam:PassRole only authorizes an entity to pass a role to an AWS service or resource during creation, not to alter the role's trust policy or its permission policies. Observing PassRole in the instance's permissions does not imply any IAM write capability.
- ✗
The instance can stop CloudTrail logging.
Why it's wrong here
Stopping CloudTrail logging requires the cloudtrail:StopLogging permission on the specific trail, which is unrelated to PassRole. Although a CloudTrail trail typically delivers events to an S3 bucket using a service role, the PassRole permission granted to the instance does not give it authority to call StopLogging or disable that delivery mechanism. Thus PassRole cannot impact the log recording state of CloudTrail.
- ✗
The instance can decrypt data encrypted with KMS keys.
Why it's wrong here
Decrypting data with KMS keys requires kms:Decrypt permission on the customer master key, which is governed by the key's key policy, key grants, and the caller's IAM policy. The iam:PassRole permission merely allows attaching a role to an EC2 instance or other service and does not confer any KMS cryptographic action. Even if the instance can pass a role, that does not automatically grant kms:Decrypt to that instance or any role.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.