SCS-C02 Identity and Access Management Practice Question
An organization wants to use AWS Organizations to centrally manage permissions for multiple accounts. Which IAM feature is used to grant cross-account access within the organization?
⚠ Common exam trap
SCS-C02 often tests the misconception that SCPs grant permissions — candidates confuse SCPs (which only limit maximum permissions) with IAM roles (which actually grant cross-account access).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM roles
IAM roles are the standard mechanism for granting cross-account access within AWS Organizations. A role in the target (trusting) account defines a trust policy that names principals in other accounts as trusted entities, and those principals call sts:AssumeRole to obtain temporary credentials scoped to the role's permissions policy. This avoids creating duplicate IAM users in every account and is the recommended pattern for centralized, auditable cross-account access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IAM roles
Why this is correct
IAM roles are the correct mechanism because they support cross-account trust relationships: the organization can configure a role in a target account with a trust policy allowing principals from a central account to assume it. When a user or service in the central account calls sts:AssumeRole, AWS STS returns temporary credentials scoped to the role's permissions policy, enabling centrally governed access across accounts. This is the standard way to grant access to AWS accounts, and it can be combined with AWS Organizations' central management for auditing and policy enforcement.
- ✗
Service control policies (SCPs)
Why it's wrong here
Service control policies are applied at the AWS Organizations account or OU level and define the maximum permissions that any principal in that account can have; they act as boundary guardrails, not grants. An SCP can deny or restrict an individual IAM role or user, but it cannot create a role, issue credentials, or allow a principal from another account to authenticate into an account. Therefore SCPs are a permission boundary control, not a mechanism for granting cross-account access.
- ✗
Resource-based policies
Why it's wrong here
Resource-based policies, such as an S3 bucket policy or a Lambda resource policy, grant access to specific resources for named principals, and some can reference cross-account principals directly without needing a role. However, they are service-specific and apply only to the individual resource that carries the policy, so they cannot serve as a general, centralized method for giving users or services access to an entire AWS account. For account-wide cross-account access, you still need an IAM role that can be assumed after the resource-based policy determines resource-level authorization.
- ✗
IAM groups
Why it's wrong here
IAM groups are simply logical collections of IAM users inside a single AWS account and are used only to attach the same permissions policies to multiple users with a consistent identity. A group has no trust relationship, no policy of its own beyond attached permissions, and cannot be assumed or referenced as a principal outside the account, so it cannot authorize access from another account. Groups exist as an administrative convenience within an account, never as a cross-account access mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.