Courseiva

SCS-C02 Identity and Access Management Practice Question

An administrator needs to grant an IAM user the ability to change their own password without allowing them to change other users' passwords. Which IAM action should be included in the policy?

⚠ Common exam trap

SCS-C02 often tests the confusion between iam:ChangePassword (self-service) and iam:CreateLoginProfile (admin creating password for others), causing candidates to pick the admin action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

iam:ChangePassword

The IAM action iam:ChangePassword allows a user to change their own password, but only if the policy is attached to that user and the request is for their own password. It does not grant permission to change other users' passwords. This is the correct action for self-service password change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    iam:CreateLoginProfile

    Why it's wrong here

    iam:CreateLoginProfile is an administrative action that creates a new password (and optional password reset requirement) for an IAM user. It is typically included in policies allowing full user management, and calling it on your own identity requires no special self-service semantics — it merely sets a profile, and IAM has no inherent check that the target is yourself. Because it does not invoke the user-change-password workflow, it fails to grant the actual self-service capability.

  • ✗

    iam:UpdateAccountPasswordPolicy

    Why it's wrong here

    iam:UpdateAccountPasswordPolicy modifies the organization-wide password policy, including parameters like minimum length, complexity requirements, and expiration age. This action does not operate on a single user's password and never affects an existing user's current credentials; it only governs rules for future password creations. The target resource is the account, not the caller, so it cannot authorize the user to change their own password.

  • ✗

    iam:UpdateServiceSpecificCredential

    Why it's wrong here

    iam:UpdateServiceSpecificCredential controls the lifecycle of service-specific credentials, such as those used for AWS CodeCommit or other services that leverage a username/password pair distinct from the console login. It does not apply to the standard IAM login password used for the management console or API signing via password. Thus, granting it gives the user ability to rotate service-specific keys, but not their own IAM password.

  • ✓

    iam:ChangePassword

    Why this is correct

    iam:ChangePassword is the precise self-service action that enables a user to update their own console password (or password used for programmatic access via the password-based APIs). When a user calls ChangePassword, IAM verifies the existing password and then replaces it, with the permission scoped to the principal's own identity. It is the only action among these options that directly corresponds to the requirement of letting a user change their own password.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.