Courseiva

CCNA Identity and Access Management Questions

75 of 151 questions · Page 1/3 · Identity and Access Management · Answers revealed

1
MCQeasy

Which IAM entity can be used to grant temporary access to AWS resources for users from a different AWS account?

A.IAM group
B.IAM role
C.IAM policy
D.IAM user
AnswerB

An IAM role is the correct entity for granting temporary access because it is designed to be assumed. When a principal assumes a role, AWS STS returns temporary security credentials with a limited lifetime, governed by the role's trust policy and permissions policy. This is the standard mechanism for federated access, cross-account access, and EC2 instance profiles.

Why this answer

An IAM role is the correct entity because it is specifically designed to grant temporary, cross-account access to AWS resources. When a user from a different AWS account assumes a role, AWS STS (Security Token Service) issues temporary security credentials (access key, secret key, and session token) that are valid for a configurable duration (default 1 hour, max 12 hours). This avoids the need to create permanent IAM users or share long-term credentials across accounts.

Exam trap

The trap here is that candidates often confuse an IAM policy with an IAM role, thinking that attaching a policy directly to an external user grants access, but policies alone cannot be assumed and do not generate temporary credentials.

How to eliminate wrong answers

Option A is wrong because an IAM group is a container for IAM users within the same AWS account and cannot be used to grant access to users from a different AWS account; it has no cross-account trust policy. Option C is wrong because an IAM policy is a document that defines permissions but is not an identity that can be assumed; it must be attached to an IAM user, group, or role to grant permissions, and by itself cannot provide temporary credentials. Option D is wrong because an IAM user is a permanent identity tied to a single AWS account; while you could create a user in your account for an external user, that would require sharing long-term access keys, which violates security best practices and does not provide temporary, scoped credentials.

2
MCQeasy

A developer needs to allow an EC2 instance to access an S3 bucket. Which is the best practice for granting permissions?

A.Store IAM user access keys in a configuration file on the EC2 instance.
B.Use a security group to allow the EC2 instance to access S3.
C.Attach an S3 bucket policy that grants access to the EC2 instance ID.
D.Create an IAM role with S3 access and attach it to the EC2 instance profile.
AnswerD

Create an IAM role with an S3 access policy, then place that role in an instance profile and attach the profile to the EC2 instance at launch or via the console/API. When the instance starts, it uses the role's trust policy to assume the role and receives temporary credentials from the instance metadata service (IMDSv1 or IMDSv2) that are automatically rotated. The SDK then uses these credentials to sign requests to S3 for the duration of the role session, enforcing the exact permissions granted by the role while avoiding the need to embed static keys.

Why this answer

The best practice for granting an EC2 instance access to S3 is to create an IAM role with the necessary S3 permissions and attach it to the EC2 instance via an instance profile. This provides temporary credentials that are automatically rotated, eliminating the need to store long-term access keys on the instance. It follows the principle of least privilege and is the most secure method.

Exam trap

SCS-C02 often tests the misconception that security groups or bucket policies can grant S3 access to EC2 instances — candidates must remember that IAM roles are the correct mechanism.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys in a configuration file on the instance is insecure — keys can be leaked, are long-term, and require manual rotation. Option B is wrong because security groups control network traffic (IP, port, protocol) and cannot grant IAM permissions to access S3; S3 access is controlled by IAM policies, not security groups. Option C is wrong because S3 bucket policies cannot grant access to an EC2 instance ID; they grant access to IAM principals (users, roles, accounts) or use conditions, but instance IDs are not valid principals.

3
MCQmedium

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that no IAM user in any account can create new IAM users. Which approach should be used?

A.Apply an IAM policy to the root user of each account.
B.Use an SCP attached to each IAM user.
C.Use an IAM permissions boundary on each IAM user.
D.Apply a service control policy (SCP) at the root organizational unit that denies IAM:CreateUser.
AnswerD

Service control policies set permission guardrails across an AWS Organizations root, and an explicit deny for iam:CreateUser applies to every principal in every member account, including account administrators. This centrally prevents new IAM users organisation-wide, satisfying the requirement without editing each account individually.

Why this answer

Service control policies (SCPs) are the correct mechanism because they allow you to centrally restrict permissions across all accounts in an AWS Organization. By attaching an SCP at the root organizational unit that denies the `iam:CreateUser` action, you ensure that no IAM user in any member account can create new IAM users, regardless of any IAM policies applied within those accounts. SCPs act as a guardrail that overrides any allow permissions granted by IAM policies.

Exam trap

The trap here is that candidates often confuse SCPs with IAM permissions boundaries or think SCPs can be attached directly to IAM users, but SCPs only apply to accounts or organizational units and are designed for centralized governance across an AWS Organization.

How to eliminate wrong answers

Option A is wrong because the root user of each account is not subject to IAM policies; the root user has full administrative access and cannot be restricted by IAM policies. Option B is wrong because SCPs are attached to AWS accounts or organizational units, not to IAM users; attaching an SCP to an IAM user is not a valid operation. Option C is wrong because an IAM permissions boundary only limits the maximum permissions an IAM user can have, but it does not prevent the user from creating other IAM users if the boundary allows it; it is not a global deny mechanism across accounts.

4
MCQmedium

A company wants to allow an IAM user to manage only their own access keys. Which IAM policy should be attached to the user?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"arn:aws:iam::*:user/*"}]}
B.{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"iam:*AccessKey*","Resource":"*"}]}
C.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"arn:aws:iam::*:user/${aws:username}"}]}
D.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"*"}]}
AnswerC

This statement is correct because the resource ARN uses the ${aws:username} variable, which automatically resolves to the IAM user name making the API call. The resulting ARN matches only that user's own IAM user resource, restricting CreateAccessKey, UpdateAccessKey, DeleteAccessKey, and similar key actions to the caller's own keys. This is the standard pattern for delegating self-service access key management while preserving separation of duties.

Why this answer

The IAM policy uses the ${aws:username} variable in the Resource element. When this policy is attached to a user, ${aws:username} resolves to that user's username, thereby restricting the actions to only that user's own access keys. Option A allows access to all users' keys.

Option B denies all AccessKey actions. Option D allows all AccessKey actions without restriction.

5
MCQeasy

An administrator needs to grant an IAM user the ability to change their own password without allowing them to change other users' passwords. Which IAM action should be included in the policy?

A.iam:CreateLoginProfile
B.iam:UpdateAccountPasswordPolicy
C.iam:UpdateServiceSpecificCredential
D.iam:ChangePassword
AnswerD

iam:ChangePassword is the precise self-service action that enables a user to update their own console password (or password used for programmatic access via the password-based APIs). When a user calls ChangePassword, IAM verifies the existing password and then replaces it, with the permission scoped to the principal's own identity. It is the only action among these options that directly corresponds to the requirement of letting a user change their own password.

Why this answer

The IAM action iam:ChangePassword allows a user to change their own password, but only if the policy is attached to that user and the request is for their own password. It does not grant permission to change other users' passwords. This is the correct action for self-service password change.

Exam trap

SCS-C02 often tests the confusion between iam:ChangePassword (self-service) and iam:CreateLoginProfile (admin creating password for others), causing candidates to pick the admin action.

How to eliminate wrong answers

Option A is wrong because iam:CreateLoginProfile is used to create a password for a user, typically an admin action for other users. Option B is wrong because iam:UpdateAccountPasswordPolicy is for setting the account password policy, an admin-level action. Option C is wrong because iam:UpdateServiceSpecificCredential is for managing service-specific credentials (e.g., for CodeCommit), not for console passwords.

6
MCQmedium

A security engineer runs the IAM policy simulator with a custom policy. The output shows the above. Which statement is true about the policy?

A.The policy allows iam:DeleteUser but denies iam:CreateUser.
B.The policy allows all actions by default.
C.The policy contains a statement that explicitly denies iam:DeleteUser.
D.The policy has no effect because the simulator returned errors.
AnswerC

The simulator's explicitDeny result for iam:DeleteUser can only be produced by a Deny statement within the policy. In IAM's evaluation logic, an explicit Deny always overrides any Allow, making the action undeniably forbidden regardless of other permissions. This matches the correct interpretation of the simulation output, as the policy visibly contains a statement that rejects DeleteUser.

Why this answer

The policy simulator shows an explicit deny for iam:DeleteUser, confirming that a deny statement exists in the policy. Option C is correct because the explicit deny means the policy explicitly denies iam:DeleteUser. Option A is incorrect because the simulator does not indicate that iam:CreateUser is denied.

Option B is incorrect because the explicit deny overrides any default allow. Option D is incorrect because the simulator returned an explicit deny, not errors.

7
Multi-Selecthard

Which FOUR are valid ways to restrict access to an S3 bucket using IAM policies? (Choose 4.)

Select 4 answers
A.Requiring server-side encryption using the 's3:x-amz-server-side-encryption' condition key
B.Using the 'aws:PrincipalOrgID' condition key
C.Restricting access to a specific VPC using the 'aws:SourceVpc' condition key
D.Using the 's3:ResourceAccount' condition key to restrict access to a specific bucket
E.Limiting access to specific IP addresses using the 'aws:SourceIp' condition key
AnswersA, B, C, E

Requiring server-side encryption via the 's3:x-amz-server-side-encryption' condition key is a valid access restriction because it makes the presence and value of the x-amz-server-side-encryption header a precondition for the S3 operation. For example, you can require that the header equals AES256 or aws:kms, which denies requests that do not carry an encryption header even if the principal otherwise has s3:PutObject permission. This condition key is evaluated per request, giving you fine-grained, attribute-based control that enforces encryption compliance on all uploads.

Why this answer

Options A, B, C, and E are all valid ways to restrict access to an S3 bucket using IAM policies. A: The 's3:x-amz-server-side-encryption' condition key can enforce server-side encryption in IAM policies. B: The 'aws:PrincipalOrgID' global condition key can be used in IAM identity-based policies to restrict access to principals from a specific AWS Organization.

C: The 'aws:SourceVpc' condition key restricts requests to those originating from a specific VPC. E: The 'aws:SourceIp' condition key restricts access to specific IP addresses. Option D is incorrect because 's3:ResourceAccount' checks the account ID of the resource, not a specific bucket; bucket-specific restriction is done via the Resource element.

8
MCQhard

A security engineer must ensure that cross-account access to an S3 bucket is restricted to only accounts that are part of a specific AWS organization. Which IAM policy condition key should be used in the bucket policy?

A.aws:SourceIp
B.aws:MultiFactorAuthPresent
C.aws:PrincipalOrgID
D.aws:SourceVpce
AnswerC

The aws:PrincipalOrgID condition key is a global condition that checks the organization ID associated with the principal's account, allowing you to require that the principal comes from an account that is a member of a specified AWS organization. In a resource-based policy, it directly validates organizational membership for cross-account access, making it the appropriate choice for ensuring that only principals from your organization can access the resource.

Why this answer

The `aws:PrincipalOrgID` condition key allows you to restrict access to only principals (accounts) that belong to a specific AWS organization. By specifying the organization ID in the bucket policy, you ensure that only accounts within that organization can access the S3 bucket, regardless of whether they are from the same account or cross-account. This key is evaluated against the organization ID of the principal's account, making it ideal for cross-account access control based on organizational membership.

Exam trap

The trap here is that candidates often confuse `aws:PrincipalOrgID` with `aws:SourceAccount` or `aws:SourceOrgID` (which does not exist), or mistakenly think `aws:SourceVpce` can restrict based on account identity, when in reality it only restricts based on network path.

How to eliminate wrong answers

Option A is wrong because `aws:SourceIp` restricts access based on the client's IP address, not the AWS account or organization, so it cannot enforce cross-account restrictions based on organization membership. Option B is wrong because `aws:MultiFactorAuthPresent` checks whether the request was authenticated with multi-factor authentication, but it does not identify the account or organization of the principal, so it cannot restrict access to specific organization accounts. Option D is wrong because `aws:SourceVpce` restricts access based on the source VPC endpoint ID, which controls network-level access but does not verify the principal's account or organization membership.

9
Multi-Selectmedium

Which TWO statements are true about IAM roles? (Choose two.)

Select 2 answers
A.IAM roles can be used by federated users.
B.IAM roles are specific to an AWS region.
C.IAM roles cannot be attached to an EC2 instance.
D.IAM roles have permanent access keys.
E.IAM roles can be assumed by AWS services like EC2.
AnswersA, E

Federated users, such as those authenticated by an external identity provider via SAML 2.0 or web identity federation, can assume an IAM role to obtain temporary AWS credentials. The user's original identity is mapped to a role, and AWS STS issues scoped, time-limited access keys that abide by the role's trust and permissions policies. This allows external identities to access AWS resources without creating an IAM user and without distributing permanent credentials.

Why this answer

Option A is correct because IAM roles support identity federation: users authenticated by an external identity provider (via SAML 2.0 or OIDC, or via AWS STS AssumeRoleWithSAML/AssumeRoleWithWebIdentity) receive temporary credentials scoped to the role's permissions rather than needing IAM user accounts. Option E is correct because AWS services can assume roles through a trust policy that names the service principal (for example, ec2.amazonaws.com), which is exactly how an instance profile lets EC2 instances obtain temporary credentials from the instance metadata service. Option B is wrong because IAM roles, like IAM users and policies, are global resources not tied to a specific AWS region.

Option C is wrong because roles are in fact attached to EC2 instances via instance profiles. Option D is wrong because roles never issue permanent access keys; they provide temporary credentials through AWS STS with automatic rotation and expiration.

Exam trap

SCS-C02 often tests the characteristics of IAM roles, and candidates might mistakenly think roles are regional or provide permanent credentials; the key is that roles are global and provide temporary credentials.

10
MCQmedium

A financial services company runs a production AWS account. A security engineer must ensure that IAM users cannot disable AWS CloudTrail logging in any region. The engineer attaches a permissions boundary to every IAM user. Which permissions boundary policy statement BEST enforces this requirement?

A.An Allow statement for cloudtrail:StopLogging with a condition that the request originates from the corporate CIDR range.
B.A Deny statement for cloudtrail:StopLogging with no conditions, plus an Allow statement for all other actions the users need.
C.A Deny statement for cloudtrail:StopLogging with a condition that aws:PrincipalTag/role equals 'security-auditor'.
D.An Allow statement for cloudtrail:* with a condition that aws:RequestedRegion is not the production region.
AnswerB

A permissions boundary with an explicit Deny for cloudtrail:StopLogging and Allow for required actions ensures no identity-based policy can override the deny. The boundary caps maximum permissions, so even if an administrator later attaches a broad policy, the deny remains effective. This directly enforces the requirement without blocking unrelated operations.

Why this answer

A permissions boundary defines the maximum permissions an identity can have, and an explicit Deny within it cannot be overridden by identity-based policies. Combining a Deny for cloudtrail:StopLogging with Allow for needed actions prevents any user from disabling logging while preserving normal access. Conditional or tag-scoped statements leave gaps that allow the prohibited action.

Exam trap

The trap here is assuming that an Allow statement with a restrictive condition is equivalent to a Deny, when only an explicit Deny in a permissions boundary can guarantee the action is blocked.

11
MCQmedium

A company has an S3 bucket with a bucket policy that grants access to an IAM role used by an application running on EC2. The application is unable to read objects from the bucket, even though the IAM role has the necessary permissions. What is the most likely cause?

A.The bucket is in a different AWS account.
B.The bucket policy denies access to the IAM role.
C.The bucket policy does not explicitly allow the IAM role.
D.The IAM role has an explicit deny statement.
AnswerB

An explicit Deny statement in the bucket policy takes precedence over every Allow, including the IAM role's identity-based permissions. In AWS authorization, the evaluation first defaults to deny, then any allow from identity-based or resource-based policy, but if an explicit deny exists in either policy, the final decision is deny. Thus if the bucket policy contains a statement that denies this role (or the role's account) the s3 operation, access will be blocked even though the role policy appears to grant the necessary permissions.

Why this answer

The most likely cause is that the bucket policy explicitly denies access to the IAM role. Even though the IAM role has the necessary permissions via its attached policies, an explicit deny in the bucket policy overrides any allow, resulting in denied access. Option A is incorrect because cross-account access can be granted with proper permissions.

Option C is incorrect because while a missing explicit allow would also deny access by default, the question says the IAM role has the necessary permissions, implying the issue is an explicit deny. Option D is incorrect because if the IAM role had an explicit deny, it would also deny access, but the role is stated to have the necessary permissions.

12
MCQhard

A security engineer is configuring AWS IAM Identity Center (successor to AWS Single Sign-On) for a company that uses an external identity provider (IdP) supporting SAML 2.0. The company wants to assign users to AWS accounts based on their groups in the IdP. The engineer has already configured the IdP and the SAML trust. What is the next step to ensure that users can access the correct AWS accounts with the appropriate permissions?

A.Use AWS Organizations SCPs to grant permissions to IdP groups based on their group names.
B.Configure IAM roles in each AWS account with trust policies that allow the IdP to assume them, and then map groups to roles.
C.In IAM Identity Center, create permission sets that define the policies, then assign the IdP groups to AWS accounts with those permission sets.
D.Create IAM users in each AWS account and map them to the IdP groups.
AnswerC

This is the correct next step. Permission sets define the level of access (e.g., read-only, admin) and are assigned to IdP groups for specific AWS accounts. This leverages the group membership from the IdP to grant access without creating individual IAM users. It centralizes management and ensures that users get the right permissions in the right accounts.

Why this answer

After configuring the SAML trust with the external IdP, the next step in IAM Identity Center is to create permission sets that define the policies for access, and then assign those permission sets to the IdP groups for specific AWS accounts. This maps group memberships to AWS permissions without creating IAM users, enabling centralized and scalable access management.

Exam trap

The trap here is thinking that IAM users or manually created IAM roles are needed when using IAM Identity Center with an external IdP, when in fact permission sets and group assignments handle everything.

13
Multi-Selecteasy

Which TWO of the following are AWS best practices for managing access keys? (Choose 2.)

Select 2 answers
A.Use the same access key for multiple users.
B.Share access keys via email.
C.Delete unused access keys.
D.Rotate access keys regularly.
E.Embed access keys directly in application code.
AnswersC, D

Unused access keys are dormant credentials that an attacker can abuse without the legitimate owner noticing, and they are frequently omitted from routine code and permission reviews. AWS provides the IAM credential report and the LastUsed timestamp for each key, so you should regularly identify keys that have not been used for 90 days and deactivate or delete them to reduce the total attack surface and simplify incident investigation.

Why this answer

AWS best practices recommend deleting unused access keys to reduce the risk of unauthorized access. Unused keys represent a potential attack vector, as they may be forgotten and left active, allowing an attacker who discovers them to gain access to AWS resources. By regularly auditing and removing keys that are no longer in use, you minimize the exposure of long-lived credentials.

Exam trap

The trap here is that candidates may think embedding keys in code is acceptable if the code is in a private repository, but AWS explicitly prohibits this practice and recommends using IAM roles or AWS Secrets Manager instead.

14
MCQhard

A security engineer is configuring a VPC endpoint for Amazon S3 and wants to ensure that only traffic from specific IAM roles can access the S3 bucket through the endpoint. Which policy element should the engineer use?

A.aws:SourceVpc
B.aws:PrincipalArn
C.aws:username
D.aws:SourceVpce
AnswerB

The aws:PrincipalArn condition key matches the full ARN of the IAM principal (user or role) that is making the request. For a VPC endpoint policy controlling access to Amazon S3, you can specify a role ARN as the value, ensuring only requests signed with that role's credentials are allowed through the endpoint. This is the correct way to restrict access to a specific IAM role because it directly inspects the principal identity rather than the network source.

Why this answer

Aws:PrincipalArn. This condition key allows you to specify the ARN of an IAM role (or user) to control access to the S3 bucket through the VPC endpoint. Option A (aws:SourceVpc) restricts traffic to a specific VPC, not an IAM role.

Option C (aws:username) is used for IAM users, not roles. Option D (aws:SourceVpce) restricts traffic to a specific VPC endpoint, not a role.

15
MCQhard

A company runs a critical application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application processes financial transactions and must store transaction logs in an Amazon S3 bucket. The security team requires that all API calls to AWS services are logged and that the logs are stored in a secure, tamper-proof manner. The team enables AWS CloudTrail to log management events and Amazon S3 server access logs for the S3 bucket. They also enable AWS Config to track resource changes. The compliance team wants to ensure that no one can disable CloudTrail logging or delete the CloudTrail log files. The security engineer proposes a solution using an SCP in AWS Organizations to deny actions that would disable CloudTrail or delete log files. However, the engineer is concerned that the SCP might be applied too broadly and affect legitimate administrative actions. The engineer wants to ensure that only the security team’s IAM role (SecurityAdminRole) can perform these restricted actions, while all other principals (including IAM users, roles, and the root user) are denied. The engineer creates an SCP that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and s3:DeleteObject on the CloudTrail S3 bucket. The SCP includes a condition that allows the action if the principal is SecurityAdminRole. However, after applying the SCP, the security team finds that even SecurityAdminRole is unable to stop CloudTrail logging. What is the most likely cause of this issue?

A.The condition in the SCP is incorrectly scoped, causing the deny to apply to all principals including SecurityAdminRole.
B.The SCP is applied to the root organizational unit (OU), which includes the management account where the root user is not affected by SCPs.
C.The SecurityAdminRole does not have the necessary IAM permissions to stop CloudTrail logging.
D.The S3 bucket policy on the CloudTrail bucket denies access to the SecurityAdminRole.
AnswerA

A service control policy (SCP) acts as a permission boundary for all IAM principals in an AWS account. In this scenario, the SCP's condition was written with incorrect scoping—it likely used a condition key that did not match the SecurityAdminRole's principal ARN, or failed to include an exclusion for that role—so the explicit deny in the SCP applied to every principal, including SecurityAdminRole. Because an explicit deny in an SCP overrides any allow from an identity-based policy, the role's IAM permission to call cloudtrail:StopLogging was ineffective, leaving the deny intact and blocking the stop action.

Why this answer

Option A is correct because the SCP's condition is likely misconfigured — for example, using a StringNotEquals on aws:PrincipalArn without accounting for the role's assumed-role ARN format, or placing the condition on the wrong element — causing the Deny to apply to all principals including SecurityAdminRole. SCPs are evaluated as a union of allows and an intersection of denies, so a mis-scoped Deny overrides any Allow.

Exam trap

SCS-C02 often tests the subtlety that SCP Deny statements with misconfigured principal conditions block everyone, including the intended exempt role — candidates forget that assumed-role ARNs differ from role ARNs.

How to eliminate wrong answers

Option B is wrong because while SCPs do not affect the management account, the scenario states SecurityAdminRole itself is blocked, which points to the condition logic, not OU placement. Option C is wrong because if the role lacked IAM permissions, the error would be an access denied from IAM, not from the SCP; the scenario says the SCP was applied and then the role was blocked. Option D is wrong because the issue is about stopping CloudTrail logging, not S3 object deletion, and a bucket policy would not block cloudtrail:StopLogging.

16
MCQeasy

A company wants to grant an IAM user the ability to rotate their own access keys. What is the least privileged IAM policy that allows this?

A.A policy with Action: 'iam:*AccessKey*' and Resource: 'arn:aws:iam::*:user/*'
B.A policy with Action: 'iam:ListAccessKeys' and 'iam:GetAccessKeyLastUsed' and Resource: '*'
C.A policy with Action: 'iam:CreateAccessKey', 'iam:DeleteAccessKey', 'iam:UpdateAccessKey' and Resource: 'arn:aws:iam::*:user/${aws:username}'
D.A policy with Action: 'iam:*' and Resource: '*'
AnswerC

This is the correct minimum-privilege policy because it grants exactly the three write actions required for access key rotation: 'iam:CreateAccessKey' to generate a new key pair, 'iam:UpdateAccessKey' to change the old key's status to Inactive, and 'iam:DeleteAccessKey' to remove the old key. The resource ARN 'arn:aws:iam::*:user/${aws:username}' uses the policy variable '${aws:username}', which is dynamically replaced with the caller's IAM user name, so each user can only manage their own access keys. This adheres to least privilege and is the AWS-recommended pattern for self-service key rotation.

Why this answer

It grants only the specific actions required to rotate access keys (CreateAccessKey, DeleteAccessKey, UpdateAccessKey) and restricts the resource to the user's own path using the ${aws:username} variable. This ensures the IAM user can only manage their own keys, adhering to the least privilege principle.

Exam trap

The trap here is that candidates often choose Option A or D because they assume wildcard actions are acceptable, but the exam tests the precise least privilege requirement by including unnecessary actions or overly broad resources that violate the principle.

How to eliminate wrong answers

Option A is wrong because 'iam:*AccessKey*' is a wildcard that includes actions like GetAccessKeyLastUsed and ListAccessKeys, which are not needed for rotation, and the resource ARN 'arn:aws:iam::*:user/*' allows access to all users, violating least privilege. Option B is wrong because it only grants read-only actions (ListAccessKeys, GetAccessKeyLastUsed) and does not include the write actions (Create, Delete, Update) necessary to actually rotate keys. Option D is wrong because 'iam:*' grants full administrative access to all IAM actions and resources, which is far beyond the minimal permissions needed for key rotation.

17
MCQeasy

An application running on an EC2 instance needs to access an S3 bucket. What is the most secure way to grant the EC2 instance the necessary permissions?

A.Create an IAM role with the necessary S3 permissions and attach it to the EC2 instance as an instance profile.
B.Store the credentials in an encrypted file on the EC2 instance and decrypt them at runtime.
C.Store the AWS access key and secret key in the application code.
D.Use an S3 bucket policy that allows access from the EC2 instance's public IP address.
AnswerA

Creating an IAM role with the necessary S3 permissions and attaching it as an instance profile is the AWS-recommended best practice. The EC2 instance receives temporary security credentials through the instance metadata service (IMDS), and the AWS SDKs automatically retrieve and refresh those credentials before they expire. This avoids storing any long-term keys on the instance, enforces least-privilege permissions scoped to the role, and gives you automatic rotation without manual intervention.

Why this answer

Attaching an IAM role to an EC2 instance via an instance profile delivers temporary, automatically rotated credentials through the Instance Metadata Service (IMDS), so no long-lived secrets exist on disk or in code. This is the AWS best practice for granting AWS service permissions to EC2 workloads and eliminates the risk of credential leakage.

Exam trap

SCS-C02 often tests whether candidates understand that instance profiles provide temporary credentials via IMDS, not static keys — the trap is choosing 'encrypted credentials on disk' because it sounds secure, when it still involves long-lived secrets.

How to eliminate wrong answers

Option B is wrong because storing credentials in an encrypted file still requires a decryption key on the instance, creating a bootstrap/secret-zero problem and leaving long-lived credentials that can be exfiltrated if the instance is compromised. Option C is wrong because hardcoding access keys in application code is the worst practice — keys end up in source control, logs, and container images, and they never rotate automatically. Option D is wrong because an S3 bucket policy keyed on the instance's public IP is fragile (IPs change on stop/start, and NAT gateways share IPs), does not authenticate the instance identity, and grants access to anyone behind that IP — it is not a secure identity-based control.

18
Multi-Selecteasy

Which THREE are valid methods for authenticating to AWS APIs? (Choose THREE.)

Select 3 answers
A.Access key ID and secret access key
B.SSH key pair
C.SAML federation
D.Client certificate
E.IAM role temporary credentials
AnswersA, C, E

Long-term IAM user credentials, an access key ID and secret access key, are the canonical way to sign AWS API requests via Signature Version 4. These credentials are used for programmatic access through the AWS CLI, SDKs, or direct HTTP calls, and must be protected with least-privilege IAM policies and rotated regularly because they do not expire by default.

Why this answer

Option A (access key ID and secret access key) is correct because long-term IAM user credentials are signed into requests via SigV4 to authenticate to AWS APIs such as the CLI, SDKs, and REST endpoints. Option C (SAML federation) is correct because AWS supports SAML 2.0-based identity federation through IAM roles and STS (AssumeRoleWithSAML), letting corporate directory users obtain temporary AWS credentials for API access. Option E (IAM role temporary credentials) is correct because STS issues short-lived credentials (access key, secret key, and session token) via AssumeRole or instance profiles, which are a standard way to authenticate API calls.

Option B (SSH key pair) is not valid for AWS API authentication, as SSH keys are used for EC2 instance login, not for signing AWS API requests. Option D (client certificate) is not a general AWS API authentication method; mutual TLS client certificates are used for specific services like IoT or API Gateway custom authorizers, not as a standard AWS API credential type.

Exam trap

SCS-C02 often tests the confusion between authentication methods for AWS APIs versus other AWS services (e.g., SSH for EC2, client certificates for API Gateway), so candidates must remember that AWS APIs specifically use IAM credentials, federation, and temporary credentials.

19
Multi-Selecthard

Which THREE of the following are characteristics of IAM roles? (Choose 3.)

Select 3 answers
A.Roles have long-term credentials like access keys.
B.Roles require a password for assumption.
C.Roles can be assumed by IAM users in another AWS account.
D.Roles have a trust policy that specifies who can assume the role.
E.Roles can be attached to EC2 instances to grant permissions to applications.
AnswersC, D, E

IAM roles support cross-account access by allowing a principal from another AWS account to assume the role, provided the role's trust policy explicitly lists that account as a trusted entity. Once assumed, the principal gains the permissions attached to the role, enabling secure federation between accounts without sharing long-term credentials. This is a common pattern for centralized management or delegated administrative tasks across AWS environments.

Why this answer

Option C is correct because IAM roles are designed for cross-account access: a role in Account A can have a trust policy granting the principal in Account B permission to call sts:AssumeRole, so users in another AWS account can assume it. Option D is correct because every IAM role has a trust policy (the AssumeRolePolicyDocument) that defines which principals (users, accounts, services, federated identities) are allowed to assume the role. Option E is correct because an instance profile delivers a role's temporary credentials to an EC2 instance, letting applications on that instance call AWS APIs with the role's permissions without embedding long-term keys.

Option A is wrong because roles do not have long-term credentials like access keys; they issue temporary credentials via AWS STS. Option B is wrong because assuming a role uses the sts:AssumeRole API and the trust policy, not a password.

Exam trap

The trap is confusing roles with IAM users, leading candidates to incorrectly believe roles have permanent credentials or require passwords, when roles actually use temporary credentials and trust policies.

20
Multi-Selectmedium

A security engineer is designing a system to allow an EC2 instance to write logs to an S3 bucket. Which TWO steps are required?

Select 2 answers
A.Configure the security group of the EC2 instance to allow outbound HTTPS traffic to S3.
B.Create a VPC endpoint for S3 in the same subnet as the EC2 instance.
C.Add a bucket policy that allows the IAM role to perform s3:PutObject.
D.Create an IAM role with a policy that allows s3:PutObject on the bucket and attach it to the EC2 instance.
E.Enable AWS CloudTrail to capture log write events.
AnswersC, D

Adding a bucket policy that explicitly allows the IAM role to perform s3:PutObject is a correct and often necessary step because S3 uses resource-based policies to control access at the bucket level. Even if the role has an identity-based policy permitting s3:PutObject, a bucket policy can grant the role as an explicit principal, which is particularly important in cross-account scenarios or when the bucket's AWS account uses S3 bucket owner enforced settings. In a same-account setup, this policy and the role policy work together to ensure the API call is allowed under the S3 policy evaluation model.

Why this answer

Options C and D are correct. The EC2 instance needs an IAM role with permissions to write to the bucket (D), and the bucket policy must allow the role to write (C). Option A is incorrect because a security group controls network traffic but does not grant IAM permissions.

Option B is incorrect because a VPC endpoint provides private connectivity but is not required for this task. Option E is incorrect because CloudTrail is for API logging, not application logs.

21
MCQeasy

A solutions architect needs to design a system where an EC2 instance can write logs to CloudWatch Logs. Which IAM entity should be used to grant permissions to the EC2 instance?

A.A resource-based policy on the EC2 instance
B.An IAM role with an instance profile
C.An IAM user with access keys stored on the instance
D.An IAM group
AnswerB

An IAM role with an instance profile is the correct approach because it provides temporary credentials to the EC2 instance through the instance metadata service (IMDSv2). The EC2 service assumes the role on behalf of the instance, and the credentials are automatically rotated and never stored as static secrets on disk. This follows the AWS security best practice of using temporary credentials for all applications running on EC2.

Why this answer

An IAM role with an instance profile is the correct approach because it allows the EC2 instance to assume temporary, rotated credentials via the AWS Security Token Service (STS). The instance profile is attached to the EC2 instance, and the AWS SDK or CLI automatically retrieves credentials from the instance metadata service (IMDS) to authenticate API calls to CloudWatch Logs. This eliminates the need to store long-term credentials on the instance and follows the principle of least privilege.

Exam trap

The trap here is that candidates may confuse IAM groups with IAM roles, thinking a group can be attached to an EC2 instance, but groups only apply to IAM users and cannot be assumed by AWS services.

How to eliminate wrong answers

Option A is wrong because a resource-based policy on an EC2 instance does not exist; EC2 instances use IAM roles (via instance profiles) for permissions, not resource-based policies like those for S3 buckets or KMS keys. Option C is wrong because storing IAM user access keys on the EC2 instance is a security risk—keys are long-term credentials that can be compromised, and AWS best practices mandate using IAM roles with temporary credentials instead. Option D is wrong because an IAM group is a container for IAM users and cannot be directly attached to an EC2 instance; permissions must be assigned via an IAM role with an instance profile.

22
MCQmedium

A company has an S3 bucket policy that allows cross-account access for a specific IAM role in another account. The bucket policy includes a Principal element with the ARN of the role. However, users in the other account that assume the role are unable to access the bucket. Which of the following is the MOST likely cause?

A.The IAM role does not have a permissions policy granting s3:GetObject on the bucket.
B.The bucket policy has an explicit Deny statement that overrides the Allow.
C.The role's trust policy does not allow the S3 service to assume the role.
D.The bucket policy uses the role ARN in the Principal element instead of the AWS account ID.
AnswerA

In cross-account S3 access, the requesting IAM role must have an identity-based permissions policy that explicitly allows s3:GetObject on the specific bucket. The bucket policy alone is insufficient; if the role lacks the necessary IAM permissions, the request is denied even when the bucket policy states that access is allowed. This missing permissions policy is the most common root cause when a role cannot read from a bucket it was supposedly granted access to.

Why this answer

For cross-account access using an S3 bucket policy, the IAM role in the trusted account must have a permissions policy that grants the necessary S3 actions (e.g., s3:GetObject). Without this policy, even if the bucket policy allows the role, the role itself does not have permission to perform the action. Options B, C, and D are less likely: B is possible but not the most common; C is incorrect because the trust policy allows users to assume the role, not the S3 service; D is incorrect because role ARNs are valid principals in S3 bucket policies.

Exam trap

Candidates often forget that the IAM role itself needs both a trust policy and a permissions policy. The bucket policy grants access to the role, but the role must also have the required permissions.

How to eliminate wrong answers

Option A is wrong because the question states the bucket policy allows cross-account access for a specific IAM role, and the issue is about the policy's Principal element, not the role's permissions policy; even if the role had an s3:GetObject permission, the bucket policy's Principal mismatch would still block access. Option B is wrong because there is no mention of an explicit Deny statement in the scenario; the problem is that the Allow statement itself is misconfigured due to the Principal element, not overridden by a Deny. Option C is wrong because the role's trust policy controls which entities can assume the role, not whether the S3 service can assume it; S3 does not assume roles—users or services assume roles, and the trust policy is irrelevant to S3 bucket policy evaluation.

23
Multi-Selectmedium

A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. Which THREE steps should the company take?

Select 3 answers
A.Create an IAM policy that denies all actions if aws:MultiFactorAuthPresent is false.
B.Enable CloudTrail to monitor MFA usage.
C.Attach the MFA enforcement policy to all IAM users or groups.
D.Set the password policy to require MFA.
E.Enable MFA for each IAM user.
AnswersA, C, E

This is the correct foundational enforcement mechanism: a Deny statement with a Bool condition on aws:MultiFactorAuthPresent. When the key evaluates to "false", the request is denied, so any API or console action by a user who did not authenticate with MFA fails. The policy can be scoped with NotAction to permit MFA self-management tasks, ensuring users can enroll without being locked out. This condition-based denial is what actually enforces MFA, unlike audit-only measures.

Why this answer

The correct steps are to enable MFA for each IAM user (E), create an IAM policy that denies all actions if `aws:MultiFactorAuthPresent` is false (A), and attach the policy to all IAM users or groups (C). Enabling MFA per user is a prerequisite. The policy enforces MFA usage by denying API calls when MFA is not present.

Attaching the policy ensures it applies to users. Option B (CloudTrail) is for auditing, not enforcement. Option D (password policy) does not enforce MFA for console access; it only sets password requirements.

24
MCQmedium

A company has multiple AWS accounts and wants to centrally manage access using IAM Identity Center (AWS SSO). Which feature allows the company to define permissions once and reuse them across multiple accounts?

A.Application assignments
B.Identity providers
C.Permission sets
D.Account assignments
AnswerC

Permission sets are the correct IAM Identity Center construct because they define reusable collections of AWS permissions, similar to IAM roles, that can be assigned to users or groups across multiple AWS accounts. You attach managed policies, customer managed policies, inline policies, permissions boundaries, and session duration to a permission set, then assign it to accounts and principals. Using permission sets lets you enforce least privilege consistently across the entire AWS Organization and change permissions in one place, which is exactly what a multi-account user-access solution requires.

Why this answer

Permission sets in IAM Identity Center define a collection of administrator-defined policies that grant specific permissions to users or groups. Once created, a permission set can be assigned to any number of AWS accounts within the organization, enabling centralized permission management and reuse across multiple accounts without duplicating policy definitions.

Exam trap

The trap here is confusing the assignment action (account assignments) with the reusable permission definition (permission sets), leading candidates to select 'Account assignments' because they focus on the deployment step rather than the reusable policy object.

How to eliminate wrong answers

Option A is wrong because application assignments are used to grant users access to third-party SAML 2.0 or OIDC applications, not to define reusable permissions for AWS accounts. Option B is wrong because identity providers (IdPs) are external authentication sources (e.g., Active Directory, Okta) that federate identities into IAM Identity Center, but they do not define or reuse permissions across accounts. Option D is wrong because account assignments associate a user or group with a specific permission set in a particular AWS account; they are the mechanism for applying permissions, not the reusable permission definition itself.

25
MCQmedium

A company uses AWS Organizations with a service control policy (SCP) that denies all actions except those explicitly listed. A developer in a member account needs to launch an EC2 instance with an IAM role that grants access to an S3 bucket. The SCP currently allows ec2:RunInstances and s3:GetObject but denies iam:PassRole. What is the MOST likely effect?

A.The developer can launch the instance, but the instance will not be able to assume the IAM role because iam:PassRole is denied.
B.The developer can launch the instance, and the instance will use the role's permissions because the SCP only applies to the developer, not the instance.
C.The developer can launch the instance if they use an existing instance profile instead of passing the role directly.
D.The developer cannot launch the instance because the SCP denies iam:PassRole, which is required to associate the role with the instance.
AnswerD

To launch an EC2 instance with an IAM role, the caller must have iam:PassRole permission for that role. An SCP that denies iam:PassRole blocks this action, so the RunInstances call fails. Even though ec2:RunInstances is allowed, the missing PassRole permission prevents the role association, making the launch unsuccessful. This is the intended security control.

Why this answer

iam:PassRole is mandatory for a principal to associate an IAM role with an EC2 instance. When an SCP denies iam:PassRole, the RunInstances action fails even if ec2:RunInstances is allowed. This prevents unauthorized role escalation.

The other options incorrectly assume the launch can succeed or misunderstand the scope of SCPs.

Exam trap

The trap here is thinking that ec2:RunInstances alone is sufficient to launch an instance with a role, forgetting that iam:PassRole is a separate required permission.

26
MCQeasy

An IAM user reports that they are unable to launch an EC2 instance in us-east-1. The IAM policy attached to the user allows ec2:RunInstances but with a condition that the instance type must be t2.micro. What could be the reason for the failure?

A.The user is trying to launch an instance type other than t2.micro.
B.The user has not attached a security group to the instance.
C.The IAM policy does not include ec2:RunInstances for us-east-1.
D.The user's account has reached the EC2 instance limit.
AnswerA

The IAM policy grants ec2:RunInstances but includes a Condition element that restricts the ec2:InstanceType to t2.micro. When the user attempts to launch any other instance type, the condition fails, causing the action to be denied even though the principal has an Allow for the action. This is an implicit deny resulting from the condition not being satisfied, not a missing action or a separate limitation. Thus, the exact reason the launch is blocked is the requested instance type falls outside the allowed value.

Why this answer

The IAM policy condition restricts ec2:RunInstances to t2.micro instances only. If the user attempts to launch any other instance type, the condition evaluates to false and the request is denied. The most likely reason for the failure is that the user is requesting a non-t2.micro instance type, which violates the policy condition.

Exam trap

SCS-C02 often tests whether candidates recognize that IAM condition keys cause implicit denies when the request does not match, rather than assuming the policy is missing the action or region.

How to eliminate wrong answers

Option B is wrong because a missing security group would cause a different error (or default to the default security group) and is not related to the IAM condition on instance type. Option C is wrong because the policy already allows ec2:RunInstances and the condition is on instance type, not region — the scenario states the user is launching in us-east-1. Option D is wrong because an EC2 instance limit would produce a different error message and is unrelated to the IAM condition on instance type.

27
MCQhard

A company uses AWS SSO to manage access to multiple accounts. An employee leaves the company. What is the most efficient way to revoke all AWS access for that employee?

A.Deactivate the user in the connected identity provider (e.g., Active Directory).
B.Delete the corresponding IAM user in every AWS account.
C.Remove the user from all groups in AWS SSO.
D.Delete the IAM role that the user assumes in each account.
AnswerA

Deactivating the user in the connected identity provider is the correct action because AWS SSO relies on the IdP as the authoritative identity source. Once the user is disabled in Active Directory (or another connected IdP), they can no longer authenticate to the AWS access portal, so no new SSO sessions or temporary AWS credentials can be issued. Any active role sessions inherited from a prior sign-in remain only until their configured session duration expires, but this operation is the only option that cleanly terminates access at the identity's source.

Why this answer

The most efficient way to revoke all AWS access for a former employee is to deactivate the user in the connected identity provider (e.g., Active Directory). AWS SSO relies on the external IdP for authentication; once the user is deactivated there, they cannot authenticate to AWS SSO, and all active SSO sessions are invalidated. This single action immediately blocks access across all accounts and applications federated through AWS SSO, without needing to touch individual IAM roles or accounts.

Exam trap

The trap here is that candidates may think AWS SSO groups or IAM roles are the primary control point, but the exam tests the understanding that the identity provider is the authoritative source for authentication, and deactivating there is the single, most efficient revocation point.

How to eliminate wrong answers

Option B is wrong because AWS SSO does not create IAM users in each account; it uses IAM roles for federated access, so there are no IAM users to delete. Option C is wrong because removing the user from all groups in AWS SSO would revoke permissions, but it requires multiple steps and does not invalidate existing sessions immediately; deactivating the user in the IdP is more efficient and ensures no new authentication is possible. Option D is wrong because deleting the IAM role that the user assumes in each account would break access for other users who might need to assume that same role, and it is an inefficient, account-by-account approach compared to a single IdP deactivation.

28
Multi-Selectmedium

Which TWO actions can be used to restrict access to an S3 bucket to only requests that originate from a specific VPC?

Select 2 answers
A.Use a security group to allow inbound traffic from the VPC to S3.
B.Use an IAM policy with a condition key aws:SourceVpce to restrict access to the VPC endpoint.
C.Configure a VPC endpoint for S3 and attach a bucket policy that allows access only from that endpoint.
D.Use a network ACL to allow traffic from the VPC to S3.
E.Use an IAM policy with a condition key aws:SourceIp to restrict access to the VPC CIDR.
AnswersB, C

When a request reaches S3 through a VPC endpoint, the request context includes the endpoint ID, so an IAM policy can use the aws:SourceVpce condition to require that the request came from that specific endpoint. This effectively blocks access from public internet or other VPCs even if the IAM principal is valid. It is a common pattern for enforcing network-layer isolation in addition to identity-based permissions.

Why this answer

The `aws:SourceVpce` condition key in an IAM policy allows you to restrict access to an S3 bucket to requests that originate from a specific VPC endpoint (VPC Endpoint ID). This ensures that only traffic coming through that VPC endpoint can access the bucket, effectively limiting access to the VPC. Option C is also correct because you can configure a VPC endpoint for S3 and attach a bucket policy that explicitly allows access only from that endpoint using the `aws:SourceVpce` condition, achieving the same restriction.

Exam trap

The trap here is that candidates often confuse IAM policies with bucket policies or think that security groups or network ACLs can directly control access to S3, but S3 is a managed service and does not process security group or NACL rules; only bucket policies and IAM policies with VPC endpoint conditions can enforce such restrictions.

29
Multi-Selecthard

Which TWO of the following are valid use cases for IAM permissions boundaries? (Choose TWO.)

Select 2 answers
A.To allow cross-account access to an S3 bucket
B.To prevent an IAM user from escalating privileges
C.To allow developers to create roles with limited permissions
D.To delegate permission management to non-administrators
E.To restrict access to an S3 bucket based on IP address
AnswersB, C

Permissions boundaries are a valid use case to prevent IAM users from escalating privileges because they set a hard ceiling on the maximum permissions a principal can receive. Even if a user is allowed to attach IAM policies to their own role, the effective permissions are the intersection of the attached policy and the boundary, so they cannot grant themselves additional privileges beyond the boundary. This mitigates the risk of an IAM user creating an administrative policy or modifying their own permissions to gain elevated access.

Why this answer

IAM permissions boundaries are a feature that allows you to set the maximum permissions that an identity-based policy can grant to an IAM entity. By attaching a permissions boundary to a user or role, you can prevent that entity from creating or modifying IAM resources (such as roles or policies) to escalate their privileges, even if their attached policies would otherwise allow it. This acts as a guardrail to enforce a hard limit on what actions the entity can perform, directly addressing privilege escalation risks.

Exam trap

The trap here is that candidates often confuse permissions boundaries with service control policies (SCPs) or resource-based policies, leading them to select options like cross-account access or IP-based restrictions, which are handled by entirely different AWS mechanisms.

30
MCQeasy

An administrator needs to allow a Lambda function to write logs to CloudWatch Logs. What is the BEST way to grant these permissions?

A.Store AWS credentials in the Lambda function code.
B.Attach a resource-based policy to the Lambda function.
C.Create an IAM role with the necessary CloudWatch Logs permissions and assign it as the Lambda function's execution role.
D.Attach the AdministratorAccess managed policy to the Lambda function's execution role.
AnswerC

Create an IAM execution role granting the Lambda function the minimal CloudWatch Logs permissions required (e.g., logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents) and attach that role to the function via the function's configuration. This identity-based policy defines what the function can do as its authorized identity, allowing it to write logs securely. Following least privilege here is correct because the role grants only the specific log-writing actions, not broader access.

Why this answer

Lambda functions assume an IAM execution role at runtime, and all AWS API calls the function makes (including CloudWatch Logs PutLogEvents) are authorized against that role's identity-based policies. Creating a role with only the required CloudWatch Logs permissions and assigning it as the execution role follows least privilege and is the standard, supported mechanism. This avoids embedding long-lived credentials and grants exactly the access needed.

Exam trap

SCS-C02 often tests whether candidates confuse resource-based policies (which grant inbound access to a resource) with execution roles (which grant outbound permissions to the function), leading them to pick option B.

How to eliminate wrong answers

Option A is wrong because hardcoding AWS credentials in Lambda code exposes long-lived secrets in source control and environment variables, violates least privilege, and is unnecessary since Lambda can assume an execution role automatically. Option B is wrong because resource-based policies are attached to resources (like S3 buckets, SNS topics, or Lambda itself for invocation) to grant other principals access, not to grant the Lambda function outbound permissions to CloudWatch Logs. Option D is wrong because AdministratorAccess grants full access to all AWS services, violating least privilege and creating a severe blast-radius risk when only logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents are required.

31
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that no IAM user in any account can create or modify IAM roles. What is the MOST effective way to enforce this?

A.Use AWS Config rules to detect role creation and automatically delete the roles.
B.Set up a Lambda function that monitors CloudTrail and revokes role creation permissions.
C.Create an SCP that denies iam:CreateRole and iam:UpdateAssumeRolePolicy and attach it to the root organizational unit.
D.Create an IAM policy that denies role creation and attach it to each user in every account.
AnswerC

This is the correct answer because an SCP attached to the root organizational unit is immediately inherited by all member accounts and acts as a preventive guardrail that cannot be overridden by any IAM policy, including the account administrator. Explicitly denying iam:CreateRole stops creation of new roles, and denying iam:UpdateAssumeRolePolicy prevents an attacker from modifying an existing role's trust policy to assume it from an untrusted account. Unlike reactive controls, SCPs take effect before the API call is allowed, and they can be managed centrally by the organization's management account.

Why this answer

The most effective way to enforce a deny across all accounts in AWS Organizations is a Service Control Policy (SCP) attached to the root organizational unit, denying iam:CreateRole and iam:UpdateAssumeRolePolicy. SCPs set the maximum permissions boundary for all principals in member accounts, so attaching a deny SCP at the root OU ensures no IAM user in any account can create or modify roles, regardless of their IAM policies. This is centralized, preventive, and cannot be bypassed by account-level admins.

Exam trap

SCS-C02 often tests the difference between preventive controls (SCPs) and detective/reactive controls (Config, Lambda) — candidates who pick reactive options miss the 'MOST effective' preventive requirement.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are detective and reactive — they detect role creation after the fact and trigger deletion, which is not preventive and leaves a window of exposure. Option B is wrong because a Lambda-based revocation is also reactive, adds latency, and is operationally fragile compared to a native preventive control. Option D is wrong because attaching an IAM deny policy to each user in every account is not scalable, can be removed by account admins, and does not cover new users or accounts — SCPs are the correct centralized mechanism.

32
MCQhard

An IAM policy has the following statement: {"Effect":"Deny","Action":"*","Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"false"}}}. What does this policy achieve?

A.Denies all actions that are not made over HTTPS
B.Allows all actions only when using HTTPS
C.Enforces HTTPS for S3 bucket policies only
D.Blocks all actions for a specific AWS service
AnswerA

This IAM policy statement uses a Deny effect with the aws:SecureTransport condition key set to 'false', so it blocks any API call that was not transmitted over a TLS/HTTPS connection. Because an explicit Deny takes precedence over all Allow statements, the policy stops every non-HTTPS request to any AWS service, while leaving HTTPS requests unaffected. The condition applies to the transport-layer security of the request itself, not to the specific action or resource, making the statement a global enforcement of HTTPS for all AWS API operations.

Why this answer

This policy statement uses the `aws:SecureTransport` condition key with a `Bool` condition set to `false`. When the condition evaluates to true (i.e., the request is not using HTTPS/TLS), the `Deny` effect applies to all actions on all resources. This effectively denies any API call made over HTTP (non-secure transport), ensuring that only HTTPS requests are allowed.

The policy does not explicitly allow anything; it only denies non-HTTPS traffic, so all actions are implicitly allowed when made over HTTPS.

Exam trap

The trap here is that candidates often confuse a `Deny` with a `Bool` condition as an implicit `Allow` for the opposite condition, but the policy only denies non-HTTPS requests and does not grant any explicit allow, so all actions are allowed by default when HTTPS is used.

How to eliminate wrong answers

Option B is wrong because the policy does not contain an `Allow` statement; it only denies non-HTTPS requests, so it does not affirmatively allow actions. Option C is wrong because the policy applies to all AWS services and resources, not just S3 bucket policies; the `Resource` is `*`, meaning it covers every service. Option D is wrong because the policy does not block all actions for a specific service; it blocks all actions across all services only when the request is not using HTTPS.

33
MCQeasy

A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The security team creates an IAM policy that denies all actions unless MFA is present. However, users report they can still perform actions without MFA. What is the most likely reason for this?

A.MFA policies only apply to API calls, not console access.
B.The policy does not include a condition to check for MFA, or the condition is incorrect.
C.The users are using root account credentials, which bypass MFA policies.
D.The policy was attached to the wrong IAM group.
AnswerB

This is the most likely reason. To enforce MFA, the policy must include a condition such as 'aws:MultiFactorAuthPresent': 'true' in a Deny statement. If the condition is missing or misspelled, the deny will not trigger. Additionally, the condition must be in a policy that applies to the users' actions. Often, administrators forget to include the condition or use the wrong key, allowing actions without MFA.

Why this answer

The most likely reason is that the policy does not include a condition to check for MFA, or the condition is incorrect. To enforce MFA, the policy must include a Deny statement with a condition like 'aws:MultiFactorAuthPresent': 'false' or 'true' depending on the logic. If the condition is missing, the deny will not be effective.

It is also important to ensure the policy is attached to all users or groups.

Exam trap

The trap here is assuming that simply creating a policy with a deny statement automatically enforces MFA, when in fact the policy must include the correct MFA condition key and be properly attached.

34
Multi-Selecthard

A security engineer is designing a permissions boundary for an IAM user. Which TWO statements about permissions boundaries are correct?

Select 2 answers
A.Permissions boundaries can be applied to service-linked roles.
B.Permissions boundaries can only be applied to IAM users, not roles.
C.The effective permissions are the intersection of the identity-based policy and the permissions boundary.
D.Permissions boundaries can override resource-based policies.
E.A permissions boundary alone does not grant permissions; an identity-based policy is also required.
AnswersC, E

A permissions boundary caps identity-based policies: the principal can only perform actions allowed by both. Effective permissions therefore equal the intersection, so an action permitted by the identity policy but absent from the boundary is denied.

Why this answer

Option C is correct because AWS evaluates a permissions boundary as a filter: the effective permissions for an IAM principal are the intersection of what the identity-based policy allows and what the permissions boundary allows, so an action must be permitted by both to succeed. Option E is correct because a permissions boundary is only a maximum-permissions guardrail; it never grants access by itself, and the principal still needs an identity-based policy (or another applicable policy) that allows the action. Options A and B are wrong because permissions boundaries can be attached to IAM users and IAM roles (including service roles), but not to service-linked roles, which are managed by AWS and do not support permissions boundaries.

Option D is wrong because permissions boundaries only limit identity-based permissions and cannot expand or override resource-based policies; resource-based policies are evaluated separately and can grant access independently of the boundary.

35
MCQmedium

A company wants to allow users from an external AWS account to assume an IAM role in its account. What must be configured in both accounts?

A.An IAM password policy in both accounts.
B.Only the trusting account's role trust policy.
C.Only the external account's IAM policy to allow sts:AssumeRole.
D.Both the trusting account's role trust policy and the external account's IAM policy to allow sts:AssumeRole.
AnswerD

Cross-account role assumption requires two grants: the trusting account's role trust policy must name the external principal, and the external account's IAM policy must permit that principal to call sts:AssumeRole. Both sides must allow it.

Why this answer

Cross-account role assumption requires a two-sided trust relationship. The trusting account (where the role lives) must have a trust policy that names the external account as a Principal and allows sts:AssumeRole. The external account must also grant its users or roles an IAM policy permitting sts:AssumeRole on the role ARN, otherwise the request is denied even if the trust policy allows it.

Exam trap

The trap is assuming that a trust policy alone is sufficient for cross-account access, when in fact AWS requires permissions on both the trusting and the calling side — a classic two-sided authorization misconception.

How to eliminate wrong answers

Option A is wrong because an IAM password policy only governs console password complexity and rotation; it has no effect on programmatic role assumption via STS. Option B is wrong because configuring only the trusting account's trust policy is insufficient — the caller's identity in the external account still needs an explicit IAM permission to call sts:AssumeRole. Option C is wrong because configuring only the external account's IAM policy is insufficient — without a trust policy in the trusting account naming the external principal, STS will reject the AssumeRole call.

36
MCQmedium

A security engineer discovers that an IAM policy allows 'iam:CreateUser' and 'iam:CreateAccessKey' for all users in the account. Which risk does this pose?

A.Users can create new IAM users and programmatic access keys
B.Users can disable CloudTrail logging
C.Users can decrypt data in S3
D.Users can modify VPC security groups
AnswerA

The policy explicitly grants IAM permissions such as iam:CreateUser and iam:CreateAccessKey. This allows an authenticated user to provision a new IAM identity and associated programmatic credentials, effectively creating a backdoor account with permissions that can be escalated to full administrative access. Because the new user and access key are fully functional and can be granted additional policies, this action represents a high-risk privilege escalation vector.

Why this answer

The IAM policy allows 'iam:CreateUser' and 'iam:CreateAccessKey', which enables users to create new IAM users and programmatic access keys, leading to unauthorized access and privilege escalation. Option B is incorrect because the policy does not grant permissions to disable CloudTrail logging. Option C is incorrect because creating users/keys does not allow decrypting data in S3.

Option D is incorrect because it does not allow modifying VPC security groups.

37
MCQmedium

A developer needs to allow an EC2 instance to read from a DynamoDB table named 'Orders' in the same account. The security team requires that the permissions be granted using an instance profile. Which steps should be taken?

A.Create an IAM role with a policy that allows dynamodb:GetItem on the 'Orders' table, create an instance profile, add the role to the profile, and launch the EC2 instance with the instance profile
B.Create an instance profile and attach a policy to it, then launch the EC2 instance with the instance profile
C.Create an IAM role with the required policy, then attach the role directly to the EC2 instance during launch
D.Create an IAM user with programmatic access, store the access key in a secure S3 bucket, and have the EC2 instance retrieve the credentials at startup
AnswerA

This is the correct and canonical method. Create an IAM role that includes a policy granting the `dynamodb:GetItem` action on the `Orders` table, define a trust policy that lets the EC2 service (`ec2.amazonaws.com`) assume it, and then create an instance profile containing that role. When you launch the EC2 instance with the instance profile, AWS automatically supplies temporary credentials through the instance metadata service (IMDSv2), so the SDK can read from DynamoDB without any stored keys. This avoids long-lived credentials and is the supported mechanism for giving an EC2 instance permissions.

Why this answer

The correct steps are to create an IAM role with the necessary policy, create an instance profile, add the role to the instance profile, and then launch the EC2 instance with that instance profile. This grants the EC2 instance temporary credentials to access DynamoDB. The instance profile is the container for the role and is required for EC2 to assume the role.

Exam trap

SCS-C02 often tests the difference between IAM roles and instance profiles. Candidates may think they can attach a role directly to an EC2 instance, but an instance profile is required. Also, they might confuse attaching policies to instance profiles instead of roles.

How to eliminate wrong answers

Option B is wrong because you cannot attach a policy directly to an instance profile; policies are attached to roles, and the role is added to the instance profile. Option C is wrong because you cannot attach an IAM role directly to an EC2 instance during launch; you must use an instance profile. Option D is wrong because using an IAM user with programmatic access and storing keys in S3 is insecure and not a best practice; it also violates the requirement to use an instance profile.

38
MCQmedium

A company wants to allow its employees to authenticate to the AWS Management Console using their existing corporate credentials. Which AWS service should be used to integrate with the company's identity provider?

A.AWS Secrets Manager
B.AWS Directory Service for Microsoft Active Directory
C.AWS Certificate Manager
D.AWS IAM Identity Center (AWS SSO)
AnswerD

AWS IAM Identity Center (formerly AWS SSO) is the purpose-built service for centrally managing workforce access and single sign-on across multiple AWS accounts, business applications, and SAML 2.0/OIDC-capable solutions. It can connect to an external identity provider (such as Okta or Azure AD) and map that provider's identity groups to AWS permission sets, issuing temporary credentials for the console or CLI. This makes it the correct choice for allowing employees to authenticate to AWS with their existing corporate credentials.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it is specifically designed to enable single sign-on (SSO) from an external identity provider (IdP) to AWS accounts and business applications. It supports federation via SAML 2.0 or OIDC, allowing employees to authenticate using their existing corporate credentials and then access the AWS Management Console without needing separate IAM users.

Exam trap

The trap here is that candidates often confuse AWS Directory Service for Microsoft Active Directory with federation, but Directory Service is for managing AD domains in AWS, not for integrating with an external corporate IdP to provide SSO to the AWS console—that requires IAM Identity Center or IAM SAML federation.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is a service for securely storing and rotating secrets (e.g., database credentials, API keys), not for federating identity or integrating with an external IdP for console access. Option B is wrong because AWS Directory Service for Microsoft Active Directory is used to create a managed Microsoft AD domain in AWS or connect to an on-premises AD, but it does not directly provide the federation layer to authenticate corporate users to the AWS Management Console via an external IdP; that requires IAM Identity Center or IAM SAML federation. Option C is wrong because AWS Certificate Manager (ACM) manages SSL/TLS certificates for securing network traffic, not identity federation or authentication to the AWS console.

39
MCQmedium

A company uses IAM roles for cross-account access. Developers in Account A need to assume a role in Account B. What must be true for the AssumeRole call to succeed?

A.Account A must have an SCP that allows sts:AssumeRole
B.The user in Account A must have MFA enabled
C.The role's trust policy must allow Account A and the user must have sts:AssumeRole permission
D.The role in Account B must have a permissions boundary
AnswerC

Correct. The trust policy of the role in Account B must include Account A as a trusted entity, and the user in Account A must have the sts:AssumeRole permission (via an IAM policy attached to their user or group).

Why this answer

For a cross-account AssumeRole call to succeed, two conditions must be met: the role in Account B must have a trust policy that allows Account A (or specific principals in Account A) to assume it, and the IAM user or role in Account A must have an identity-based policy granting sts:AssumeRole on that role. Both are required; missing either results in Access Denied.

Exam trap

SCS-C02 often tests the two-sided nature of AssumeRole — candidates frequently forget that both the trust policy and the caller's identity policy must allow the action, and may incorrectly select an answer that only addresses one side or confuses SCPs with permission grants.

How to eliminate wrong answers

Option A is wrong because SCPs apply only to accounts in AWS Organizations and restrict permissions — they do not grant permissions, and they are not required for cross-account access unless the account is in an organization with restrictive SCPs. Option B is wrong because MFA is not a default requirement for AssumeRole; it can be enforced via a condition in the trust policy, but it is not mandatory. Option D is wrong because a permissions boundary sets the maximum permissions for an identity, but it does not grant the ability to assume a role — it is a limiting factor, not a granting mechanism.

40
MCQeasy

A company requires that all access to its S3 buckets be logged for compliance. Which AWS service should be used to record API calls to S3?

A.Amazon GuardDuty
B.Amazon Inspector
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail records S3 API activity, including object-level data events when enabled, satisfying the compliance requirement to log all bucket access. Unlike S3 server access logging, which captures only bucket-level requests, CloudTrail delivers detailed API call records to an S3 bucket or CloudWatch Logs for auditing.

Why this answer

AWS CloudTrail records API calls for auditing purposes, making it the correct service for logging access to S3 buckets. Option A is incorrect because Amazon GuardDuty is a threat detection service, not a logging service. Option B is incorrect because Amazon Inspector assesses vulnerabilities.

Option C is incorrect because AWS Config tracks resource configuration changes, not API calls.

41
MCQmedium

A security engineer is investigating an IAM role that was used to access AWS resources from an external account. The role has a trust policy that allows the external account to assume it. Which of the following is a required step for the external account to use the role?

A.Configure the role to require MFA for the external account.
B.Create a new IAM role in the external account with a trust policy allowing the role's ARN.
C.Add the external account's root user ARN to the role's trust policy.
D.Attach an IAM policy to an IAM user in the external account that allows sts:AssumeRole for the role ARN.
AnswerD

Cross-account access needs two sides: the trust policy in the owning account and an identity-based policy in the external account granting sts:AssumeRole on the role ARN. Without that permission attached to the calling principal, the AssumeRole call is denied.

Why this answer

For an external account to assume an IAM role in another account, an IAM user or role in the external account must have an IAM policy that allows the sts:AssumeRole action for the role's ARN. This is a required step because the external account's identity needs permission to call AssumeRole. The trust policy on the role allows the external account to assume it, but the external account must also grant its own identity the permission to assume that role.

Exam trap

SCS-C02 often tests the two-sided permission requirement for cross-account role assumption; candidates may forget that the external account must also have an identity-based policy allowing sts:AssumeRole, not just the trust policy on the role.

How to eliminate wrong answers

Option A is wrong because requiring MFA is an optional security enhancement, not a required step for the external account to use the role. Option B is wrong because creating a new IAM role in the external account with a trust policy allowing the role's ARN is not required; the external account can use an IAM user or role with the appropriate AssumeRole policy. Option C is wrong because adding the external account's root user ARN to the trust policy is not required; the trust policy typically specifies the account ID or a specific principal, and the root user is not the only way.

42
Multi-Selectmedium

Which THREE of the following are best practices for managing IAM access keys? (Choose THREE.)

Select 3 answers
A.Use IAM roles for EC2 instances instead of access keys
B.Use long-lived access keys for applications
C.Delete unused access keys
D.Embed access keys in application code for convenience
E.Rotate access keys regularly
AnswersA, C, E

IAM roles for Amazon EC2 instances provide temporary security credentials through the instance metadata service, eliminating the need to store any long-term secret material inside the instance. These credentials are automatically rotated and can be scoped with a precise permissions policy, so even if the instance is compromised, the blast radius is limited. This approach also simplifies key management because there is no auth material to embed, rotate, or revoke individually.

Why this answer

Option A is correct because IAM roles deliver temporary credentials to EC2 instances via the instance metadata service, eliminating the need to store long-lived access keys on the instance and automatically rotating credentials. Option C is correct because unused access keys represent an unnecessary attack surface; deleting them (or deactivating them first) removes the risk of leaked or forgotten credentials being abused. Option E is correct because regularly rotating access keys limits the window of exposure if a key is compromised and aligns with AWS guidance to rotate keys periodically.

Options B and D are not best practices: long-lived keys increase exposure risk, and embedding keys in application code makes them hard to rotate and easy to leak through source control or logs.

Exam trap

SCS-C02 often tests the misconception that long-lived access keys are acceptable for convenience — candidates may pick 'use long-lived keys' or 'embed keys in code' as valid practices when they are explicitly discouraged.

43
MCQeasy

A company wants to allow an external auditor to assume a read-only role in their AWS account. The auditor's AWS account ID is 123456789012. Which trust policy should be attached to the role?

A.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::123456789012:root" }, "Action": "sts:AssumeRole", "Condition": { "Bool": { "aws:MultiFactorAuthPresent": "true" } } } ] }
B.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::123456789012:root" }, "Action": "sts:AssumeRole" } ] }
C.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::123456789012:user/Auditor" }, "Action": "sts:AssumeRole" } ] }
D.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Principal": { "AWS": "123456789012" }, "Action": "sts:AssumeRole" } ] }
AnswerA

This trust policy is correct because it grants the external account's root principal (arn:aws:iam::123456789012:root) permission to call sts:AssumeRole only when the aws:MultiFactorAuthPresent condition evaluates to true. This enforces that any IAM principal from that account must have authenticated with an MFA device before assuming the role, which is a security best practice for external auditors. Using the account root ARN as Principal is the standard pattern because it delegates the actual user and role management to the external account.

Why this answer

It grants the external auditor's AWS account (via its root principal ARN) permission to assume the read-only role, while enforcing multi-factor authentication (MFA) as a security best practice. The `sts:AssumeRole` action is the standard mechanism for cross-account role assumption, and the `aws:MultiFactorAuthPresent` condition ensures the auditor uses MFA, reducing the risk of compromised credentials.

Exam trap

The trap here is that candidates often overlook the MFA condition or incorrectly specify a specific user ARN, failing to recognize that the root principal ARN is the correct way to grant access to an entire external account while maintaining flexibility and security.

How to eliminate wrong answers

Option B is wrong because it lacks the MFA condition, which is a critical security control for external access; without it, the auditor could assume the role without MFA, violating the principle of least privilege and increasing risk. Option C is wrong because it specifies a specific IAM user (`user/Auditor`) rather than the entire account (`root`), which is inflexible and would require updating the policy if the auditor's username changes or if multiple auditors need access. Option D is wrong because it uses `Deny` instead of `Allow`, which would explicitly block the auditor from assuming the role, and the principal format is invalid (missing `arn:aws:iam::` prefix).

44
Multi-Selecteasy

Which TWO are IAM best practices? (Choose two.)

Select 2 answers
A.Avoid using IAM roles and instead attach policies directly to users.
B.Use the root user for everyday administrative tasks.
C.Grant broad permissions to all users to simplify management.
D.Use conditions in IAM policies to restrict access based on tags or IP addresses.
E.Use IAM roles for applications that run on EC2 instances.
AnswersD, E

IAM policy conditions allow you to add context-aware requirements to an allow statement, such as restricting the source IP with 'aws:SourceIp', requiring an MFA token with 'aws:MultiFactorAuthPresent', or limiting EC2 actions based on resource tags with 'ec2:ResourceTag'. This goes beyond identity alone by enforcing that the request also looks like it comes from a trusted network or satisfies other organizational controls. Conditions are a core defense against stolen credentials and are essential for implementing least privilege in real-world environments where access should depend on more than just who is calling.

Why this answer

Using conditions in IAM policies (e.g., `aws:SourceIp`, `aws:RequestTag`) allows you to enforce fine-grained access control based on contextual attributes like IP addresses or resource tags. This follows the principle of least privilege by restricting permissions to only the necessary scope, reducing the attack surface. For example, you can deny access to S3 buckets unless the request originates from a corporate IP range.

Exam trap

The trap here is that candidates often confuse IAM roles with IAM users, mistakenly thinking roles are only for cross-account access, when in fact roles are the recommended mechanism for granting permissions to AWS services like EC2, Lambda, and ECS.

45
MCQmedium

A company wants to allow users from its corporate Active Directory to access AWS resources. The company has set up an IAM identity provider for SAML. What must be created in IAM to map users to permissions?

A.An IAM role with a trust policy for the SAML provider
B.An OIDC identity provider
C.An IAM user for each Active Directory user
D.A federation role type
AnswerA

For SAML federation, the correct pattern is an IAM role with a trust policy that grants sts:AssumeRoleWithSAML to the SAML identity provider you create in IAM. The corporate Active Directory is the external IdP (for example, AD FS or Shibboleth), and the trust policy uses the IAM SAML provider's ARN as the principal, often with an audience condition of urn:amazon:webservices. When a user authenticates to AD, the IdP issues a SAML assertion, AWS validates it against the SAML provider, and the user receives temporary credentials scoped by that role's permissions. This achieves single sign-on without creating or maintaining AWS credentials for each AD user.

Why this answer

A is correct because when using SAML-based federation, IAM roles are the mechanism to grant permissions to federated users. The role must have a trust policy that specifies the SAML identity provider as the principal, allowing users authenticated by the corporate Active Directory to assume the role and obtain temporary AWS credentials. This maps the SAML assertion attributes (such as the user's group or role) to IAM permissions via the role's permissions policy.

Exam trap

The trap here is that candidates confuse the IAM role trust policy with the SAML identity provider configuration itself, thinking the provider alone grants permissions, rather than understanding that the role bridges the SAML assertion to AWS permissions.

How to eliminate wrong answers

Option B is wrong because OIDC (OpenID Connect) is a separate identity federation protocol used for web identity providers like Google or Amazon Cognito, not for SAML-based Active Directory federation. Option C is wrong because creating an IAM user for each Active Directory user defeats the purpose of federation—it would require managing duplicate identities and credentials outside the corporate directory. Option D is wrong because 'federation role type' is not a valid IAM entity; IAM roles are categorized by trust policy type (e.g., service role, cross-account role, or identity provider role), but there is no distinct 'federation role type' in the AWS API or console.

46
MCQmedium

A security engineer notices that an IAM role has a trust policy allowing any AWS account to assume it. Which attack is this misconfiguration most likely to enable?

A.Logging bypass via CloudTrail
B.Cross-service confused deputy attack
C.Unauthorized access by an external attacker
D.Privilege escalation by attaching additional policies
AnswerC

This is correct: an overly broad trust policy—for example `"Principal": "*"` without restrictive conditions—allows any AWS principal from any account to call `sts:AssumeRole` and obtain the role's temporary security credentials. Once assumed, the attacker receives all permissions attached to the role, enabling unauthorized actions in the account. In the absence of conditions like `aws:PrincipalArn`, `aws:PrincipalAccount`, or an external ID, there is no mechanism to distinguish legitimate principals from external attackers, so the role effectively exposes its permissions to the entire AWS ecosystem.

Why this answer

An IAM role trust policy that allows any AWS account (i.e., `"Principal": {"AWS": "*"}`) to assume the role means that any user or service in any AWS account can call the STS `AssumeRole` API to obtain temporary credentials for the role. This directly enables unauthorized access by an external attacker who can discover the role ARN and assume it, gaining all permissions attached to the role.

Exam trap

The trap here is that candidates may confuse a trust policy misconfiguration with a permissions policy misconfiguration, thinking that privilege escalation (Option D) is the primary risk, when in fact the trust policy directly controls who can assume the role, making unauthorized access the immediate and most likely attack.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs all AWS API calls, including STS `AssumeRole` actions, and there is no mechanism in this misconfiguration to bypass or disable CloudTrail logging. Option B is wrong because a cross-service confused deputy attack involves a malicious service tricking another service into using its own permissions, not an overly permissive trust policy allowing any AWS account to assume a role. Option D is wrong because the misconfiguration is in the trust policy, not in the permissions policy; privilege escalation by attaching additional policies would require the attacker to already have IAM permissions to modify policies, which is not enabled by the trust policy alone.

47
Multi-Selecthard

Which THREE are best practices for securing IAM in an AWS environment? (Choose THREE.)

Select 3 answers
A.Use IAM roles for applications running on EC2.
B.Enable MFA for all IAM users.
C.Use the AWS account root user for daily administrative tasks.
D.Grant broad permissions to simplify management.
E.Rotate IAM user access keys regularly.
AnswersA, B, E

IAM roles allow EC2 instances to obtain temporary security credentials automatically through instance profiles, eliminating the need to embed long-term access keys on the instance. These temporary credentials are vended via the instance metadata service and are rotated by AWS STS, reducing the risk of leaked keys and their blast radius. Roles also let you enforce least privilege cleanly, because you can attach narrowly scoped policies to the role and update them without modifying the instance.

Why this answer

Using IAM roles for EC2 instances eliminates the need to store long-term AWS credentials (access keys) on the instance. Instead, the instance assumes the role via the EC2 metadata service, which automatically rotates temporary security credentials (via AWS STS). This follows the principle of least privilege and reduces the risk of credential leakage.

Exam trap

The SCS-C02 exam often tests the misconception that the root user is acceptable for daily tasks because it has full access, but the trap is that the root user lacks granular audit trails and cannot be restricted by IAM policies, making it a massive security risk for routine operations.

48
Multi-Selecthard

A security engineer needs to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which condition must be configured?

Select 1 answer
A.aws:SourceIp
B.aws:UserAgent
C.aws:SourceVpce
D.aws:SourceVpc
E.aws:Referer
AnswersC

aws:SourceVpce is the correct condition key because it restricts access to requests that arrive through a specific VPC endpoint, identified by its endpoint ID (e.g., vpce-1234567890abcdef0). This condition is evaluated based on the endpoint's identity, which cannot be spoofed or altered through IP address translation, providing a reliable network-level control. It ensures that only traffic coming from that exact VPC endpoint is allowed to access the S3 bucket.

Why this answer

To restrict S3 bucket access to a specific VPC endpoint, the bucket policy must include a condition that checks the VPC endpoint ID. The condition key `aws:SourceVpce` evaluates the endpoint ID of the VPC endpoint through which the request arrives. This ensures that only requests originating from that specific endpoint are allowed, effectively blocking access from the public internet or other endpoints.

Exam trap

SCS-C02 often tests the difference between `aws:SourceVpce` and `aws:SourceVpc`; candidates may confuse VPC ID with VPC endpoint ID, leading to selection of the wrong condition key.

49
MCQeasy

A developer needs to grant an IAM user access to a specific S3 bucket only. Which IAM policy element should be used to restrict access to that bucket?

A.Principal
B.Condition
C.Resource
D.Action
AnswerC

The Resource element is the only policy element that specifies which service resources the action applies to, using Amazon Resource Names (ARNs). To grant an IAM user access to a specific S3 bucket, you must include that bucket's ARN in the Resource field, optionally with a wildcard for objects. Without the correct Resource entry, the policy cannot define the scope of access needed.

Why this answer

The Resource element in an IAM policy specifies the AWS resource(s) to which the policy statement applies. For an S3 bucket, you use the bucket's ARN (e.g., arn:aws:s3:::bucket-name) or its objects (arn:aws:s3:::bucket-name/*) in the Resource field to restrict access to that specific bucket. This directly scopes the permissions to the intended bucket, ensuring the IAM user can only perform allowed actions on that resource.

Exam trap

SCS-C02 often tests the confusion between identity-based and resource-based policy elements, leading candidates to incorrectly choose Principal or Condition when asked how to restrict access to a specific resource in an identity-based policy.

How to eliminate wrong answers

Option A is wrong because Principal is used in resource-based policies (like S3 bucket policies) to specify who (user, role, account) is allowed or denied access, not in identity-based policies to restrict resources. Option B is wrong because Condition adds constraints (e.g., IP range, MFA, time) but does not by itself limit access to a specific bucket; it only refines when a policy applies. Option D is wrong because Action defines the operations (e.g., s3:GetObject) but does not specify which bucket those actions can be performed on.

50
MCQeasy

A company wants to allow its development team to have full access to Amazon S3 buckets that are tagged with 'Environment: Dev'. Which IAM policy element should be used to restrict access based on tags?

A.Use 'aws:PrincipalTag' in the Condition element
B.Use 'aws:SourceTag' in the Condition element
C.Use 'aws:RequestTag' in the Condition element
D.Use 'aws:ResourceTag' in the Condition element
AnswerD

aws:ResourceTag allows you to write a condition such as StringEquals: aws:ResourceTag/Project: Dev, which is evaluated against tags attached to the resource that the request targets. This AWS global condition key supports attribute-based access control and works in both identity-based and resource-based policies. It directly enforces that a developer can only perform an action when the specific resource has the required tag key-value pair, making it the correct choice for this requirement.

Why this answer

To restrict access based on tags attached to the S3 bucket (the resource), the IAM policy must use the aws:ResourceTag condition key. This key evaluates the tags on the target resource, allowing or denying actions only when the resource carries the specified tag, such as Environment: Dev.

Exam trap

SCS-C02 often tests the distinction between aws:ResourceTag (tags on the target resource) and aws:PrincipalTag (tags on the caller); candidates frequently confuse the two and select PrincipalTag when the question asks about resource tags.

How to eliminate wrong answers

Option A is wrong because aws:PrincipalTag evaluates tags on the IAM principal making the request, not on the target resource. Option B is wrong because aws:SourceTag is not a valid IAM condition key; it does not exist in AWS policy language. Option C is wrong because aws:RequestTag is used to control which tags can be applied during resource creation or modification, not to restrict access to already-tagged resources.

51
MCQmedium

A company is using IAM roles to grant EC2 instances access to an S3 bucket. The security team wants to ensure that the instances can only access their own bucket. Which policy should be attached to the IAM role to enforce this?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:*","Resource":"*"}]}
B.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:GetObject","Resource":"*"}]}
C.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:GetObject","Resource":"*","Condition":{"IpAddress":{"aws:SourceIp":"10.0.0.0/16"}}}]}
D.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}]}
AnswerD

This is the correct least-privilege policy: it restricts the s3:GetObject action to a specific Resource ARN, arn:aws:s3:::my-bucket/*, which matches only objects inside the my-bucket bucket. The lack of s3:ListBucket permission is fine for direct object retrieval—the caller must know the object key, but that matches the requirement of granting access to the bucket's objects. The policy contains no wildcards beyond the object-name segment (*), so it does not grant access to other buckets or to bucket-level operations like listing. This scoping aligns with AWS's recommended practice of using resource-level permissions for S3 actions and is the only option that satisfies the principle of least privilege.

Why this answer

Option D is the only policy that scopes the Allow to a specific bucket ARN (arn:aws:s3:::my-bucket/*), which enforces least privilege by ensuring the role can only access objects in that one bucket. The other options either grant wildcard access or use conditions that do not restrict the resource to the instance's own bucket.

Exam trap

The trap is picking a policy that 'looks' scoped (e.g., with an IP condition) but still uses Resource:* — the exam tests whether you verify the Resource element, not just the presence of a Condition.

How to eliminate wrong answers

Option A is wrong because it grants s3:* on Resource:* — full S3 access to every bucket in the account, the opposite of least privilege. Option B is wrong because it allows s3:GetObject on Resource:* — read access to objects in any bucket, not just the instance's own bucket. Option C is wrong because while it adds an IP condition, the Resource is still '*' and the SourceIp condition is unreliable for EC2 (the instance's private IP is not what S3 sees for gateway endpoint traffic; S3 sees the VPC endpoint or NAT IP), so it does not correctly scope access to the instance's bucket.

52
MCQhard

A security engineer needs to allow an application running on an Amazon EC2 instance to access an Amazon S3 bucket. The application must not use long-term credentials. The engineer has created an IAM role with the necessary permissions and attached it to the instance profile. However, the application is still receiving access denied errors. Upon investigation, the engineer finds that the application is using the AWS SDK for Java and is explicitly setting credentials via environment variables. What is the MOST likely cause of the access denied errors?

A.The IAM role's trust policy does not allow the EC2 service to assume the role.
B.The environment variables contain credentials that are expired or lack the necessary permissions.
C.The S3 bucket policy denies access to the IAM role associated with the instance profile.
D.The EC2 instance metadata service is disabled, preventing the SDK from retrieving temporary credentials.
AnswerB

When environment variables are set, the AWS SDK prioritizes them over the instance profile credentials. If those credentials are expired or have insufficient permissions, the application will receive access denied errors even though the instance profile role has the correct permissions. The SDK does not fall back to the instance profile when explicit credentials are provided.

Why this answer

The AWS SDK credential provider chain checks environment variables before instance profile credentials. If the application sets AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY, those credentials are used exclusively. If they are expired or lack permissions, access is denied.

The solution is to remove the environment variables so the SDK uses the instance profile's temporary credentials.

Exam trap

The trap here is assuming that attaching an IAM role to an EC2 instance automatically overrides any manually configured credentials, when in fact explicit environment variables take precedence in the SDK's credential provider chain.

53
MCQmedium

A company has an S3 bucket that contains sensitive data. The security team wants to ensure that all access to the bucket is encrypted in transit. What is the most effective way to enforce this?

A.Enable default encryption on the S3 bucket using SSE-S3.
B.Enable AWS CloudTrail to log all S3 access and alert on non-HTTPS requests.
C.Add a bucket policy that denies access if the request does not use HTTPS (aws:SecureTransport condition).
D.Create an IAM policy that denies S3 actions without the condition aws:SecureTransport.
AnswerC

Adding a bucket policy with a Deny effect and the condition `aws:SecureTransport: false` will reject any request that is not sent over SSL/TLS. This is the most direct and comprehensive way to enforce HTTPS on S3 because the bucket policy is evaluated for every request to the bucket, regardless of which IAM principal, account, or anonymous user makes it. Using a resource-based policy at the bucket level also aligns with AWS best practices for S3 security and is the recommended mechanism to mandate encrypted connections.

Why this answer

A bucket policy with the aws:SecureTransport condition denies any request that does not use HTTPS, enforcing encryption in transit. Option A is incorrect because SSE-S3 only encrypts data at rest, not during transmission. Option B is incorrect because CloudTrail logs access but does not enforce encryption.

Option D is incorrect because an IAM policy can deny non-HTTPS requests, but enforcing this at the bucket policy level is more direct and applies to all principals accessing the bucket.

54
MCQeasy

A developer needs to grant an EC2 instance read-only access to an S3 bucket. Which of the following is the most secure way to provide these permissions?

A.Use an IAM role and store the credentials in AWS Systems Manager Parameter Store, then retrieve them at instance launch.
B.Create an IAM role with read-only access and attach it to the EC2 instance profile.
C.Create a bucket policy that grants read-only access to the instance's public IP address.
D.Create an IAM user with read-only access and store the access keys in the instance's user data.
AnswerB

An IAM role attached to the instance profile supplies temporary, automatically rotated credentials to the EC2 instance, avoiding long-term access keys on the instance. This satisfies the requirement for read-only S3 access using the most secure mechanism.

Why this answer

Using an IAM role attached to an instance profile grants temporary credentials and eliminates long-term access keys. Option A is incorrect because storing credentials in Parameter Store (or any static storage) is less secure than using an instance profile, and IAM roles do not have static credentials to store. Option C is incorrect because a bucket policy cannot grant access based on an instance's public IP in a secure or reliable way, and it would grant access to anyone with that IP, not just the instance.

Option D is incorrect because storing IAM user access keys in user data exposes long-term credentials, which is less secure than using an instance profile.

55
MCQhard

Refer to the exhibit. An IAM policy allows running EC2 instances. A developer tries to launch a t2.micro instance but receives an 'AccessDenied' error. What is the most likely reason?

A.The policy does not grant permissions for other required resources such as images or security groups.
B.The developer is trying to launch a different instance type.
C.The region in the policy does not match the developer's region.
D.The policy has an explicit deny elsewhere.
AnswerA

Launching an EC2 instance requires more than the `ec2:RunInstances` action; the policy must also allow dependent resources. The `RunInstances` call authorises each referenced AMI, security group, subnet and key pair, so a policy granting only the run action fails with `AccessDenied` when those resource-level permissions are absent.

Why this answer

Even though the policy allows the ec2:RunInstances action on the instance resource, the RunInstances API call requires permissions for other resources such as Amazon Machine Images (AMI), security groups, and key pairs. Without explicit permissions for these resources, the API call fails with an AccessDenied error. Option B is incorrect because the condition specifies t2.micro, matching the developer's request.

Option C is incorrect because the policy does not restrict by region. Option D is incorrect because there is no explicit deny; the denial is due to missing resource permissions.

56
MCQeasy

A company wants to allow a Lambda function to read objects from an S3 bucket in the same account. What should be done?

A.Store IAM user access keys in the Lambda function's environment variables.
B.Create an IAM role with an S3 read policy and attach it to the Lambda function.
C.Add a bucket policy allowing s3:GetObject for the Lambda service principal.
D.Configure the S3 bucket to be public.
AnswerB

Create an IAM role with a policy allowing s3:GetObject on the specific bucket and object ARNs, then set that role as the Lambda function's execution role. The role's trust policy must allow lambda.amazonaws.com to assume it, after which Lambda calls STS to receive temporary credentials scoped to that role. These credentials are automatically rotated and passed to the AWS SDK, making this the least-privilege, auditable way to grant the function read access to S3.

Why this answer

Lambda functions require an IAM role (execution role) to obtain temporary AWS credentials via the AWS Security Token Service (STS). Attaching a policy with s3:GetObject permissions to this role grants the Lambda function the necessary access to read objects from the S3 bucket without hardcoding long-term credentials.

Exam trap

The trap here is that candidates confuse the Lambda service principal (lambda.amazonaws.com) with the Lambda execution role, incorrectly assuming that a bucket policy can grant access directly to the Lambda service rather than to the IAM role that the Lambda function assumes.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys in environment variables violates security best practices (long-term credentials are exposed and must be rotated manually), and Lambda natively supports temporary credentials via an execution role. Option C is wrong because a bucket policy that grants s3:GetObject to the Lambda service principal (lambda.amazonaws.com) does not work—the service principal cannot be used as a grantee in a resource-based policy; instead, you must specify the IAM role ARN or the AWS account root user. Option D is wrong because making the S3 bucket public exposes all objects to the internet, which is a severe security risk and unnecessary when a properly scoped IAM role can grant access only to the Lambda function.

57
MCQmedium

An organization wants to enforce multi-factor authentication (MFA) for all IAM users who perform sensitive actions. Which condition key should be used in an IAM policy to require MFA?

A.aws:SourceIp
B.aws:MultiFactorAuthPresent
C.aws:UserAgent
D.aws:CurrentTime
AnswerB

aws:MultiFactorAuthPresent is the correct global condition key because it is a Boolean request context key that indicates whether the principal authenticated with an MFA device. By adding a condition such as "Bool": {"aws:MultiFactorAuthPresent": "true"} to an IAM policy, administrators can require every matching request to come from a session that has completed MFA. This directly enforces the organization's MFA requirement and cannot be substituted by IP, client, or time-based checks.

Why this answer

The condition key 'aws:MultiFactorAuthPresent' is used in IAM policies to check whether the principal authenticated with MFA. When set to 'true' in a policy condition, it requires that the user has presented a valid MFA token for the request to be allowed, making it the correct choice for enforcing MFA on sensitive actions.

Exam trap

The trap is confusing 'aws:MultiFactorAuthPresent' with other condition keys like 'aws:SourceIp' or 'aws:CurrentTime', or not realizing that it only works with temporary credentials, leading to ineffective MFA enforcement.

How to eliminate wrong answers

Option A is wrong because 'aws:SourceIp' restricts access based on the source IP address, not MFA status. Option C is wrong because 'aws:UserAgent' checks the user agent string of the client, which is not related to MFA. Option D is wrong because 'aws:CurrentTime' restricts access based on the current date and time, not MFA.

58
Multi-Selectmedium

Which TWO actions can be performed using AWS IAM? (Choose two.)

Select 2 answers
A.Change the instance type of an RDS database
B.Create a CloudFront distribution
C.Define a password policy for IAM users
D.Create an IAM role with a trust policy for EC2
E.Configure a VPC peering connection
AnswersC, D

Defining an account password policy is a core IAM feature: IAM provides the UpdateAccountPasswordPolicy API and a dedicated console page to enforce policies such as minimum password length, complexity, expiration, and reuse prevention for all IAM users. This policy is stored and enforced by the IAM service as part of its identity-management responsibilities. Since IAM directly manages user credentials, password policy configuration is one of the two actions correctly performed using AWS IAM.

Why this answer

AWS IAM allows you to define a password policy for IAM users, which enforces complexity requirements, rotation periods, and reuse prevention. This is a core IAM feature that helps secure user credentials without relying on external identity providers.

Exam trap

The trap here is that candidates confuse IAM's authorization capabilities (granting permissions) with the ability to directly perform resource operations, leading them to select options like A, B, or E that are actual AWS actions but are not performed by IAM itself.

59
MCQmedium

An organization wants to enforce multi-factor authentication (MFA) for all IAM users accessing the AWS Management Console. Which policy should be used?

A.A policy that allows all actions and denies when aws:MultiFactorAuthPresent is true.
B.A policy that allows all actions except ConsoleLogin unless MFA is present.
C.A policy that allows all actions when aws:MultiFactorAuthPresent is true.
D.A policy that denies all actions unless aws:MultiFactorAuthPresent is true.
AnswerD

This is the correct enforcement pattern: a Deny statement with the condition aws:MultiFactorAuthPresent equal to false (or using BoolIfExists to treat a missing key as false) explicitly blocks every action from principals that did not use MFA. Because explicit Deny statements take precedence over any Allow, attaching this policy ensures no other policy can accidentally allow unauthenticated-with-MFA access. This is the standard AWS-recommended way to enforce MFA across all AWS API actions.

Why this answer

It uses an IAM policy with a Deny effect on all actions when `aws:MultiFactorAuthPresent` is false (or not true). This ensures that any IAM user attempting to perform any action, including ConsoleLogin, must have authenticated with MFA; otherwise, the request is denied. This is the standard approach to enforce MFA for all AWS Management Console access.

Exam trap

The trap here is that candidates often confuse the condition key evaluation — thinking a policy that 'allows when MFA is present' is sufficient, but without an explicit Deny for when MFA is absent, other policies could still grant access, making the enforcement incomplete.

How to eliminate wrong answers

Option A is wrong because it denies actions when `aws:MultiFactorAuthPresent` is true, which would block users who have authenticated with MFA, defeating the purpose. Option B is wrong because it allows all actions except ConsoleLogin unless MFA is present, but it does not deny other actions (like API calls) when MFA is absent, leaving a security gap. Option C is wrong because it allows all actions when MFA is present but does not explicitly deny actions when MFA is absent, meaning a user without MFA could still access resources if another policy grants access.

60
MCQhard

A company uses AWS Organizations with SCPs. The SCP for the production OU denies all actions on DynamoDB. An IAM policy attached to a user in that OU allows dynamodb:PutItem. What is the effective access?

A.The user can perform PutItem because the IAM policy allows it.
B.The user cannot perform PutItem because the SCP denies all DynamoDB actions and IAM allows are overridden.
C.The user cannot perform PutItem because the SCP applies only to the root account.
D.The user can perform PutItem only if the SCP has an explicit allow.
AnswerB

The SCP explicitly denies all DynamoDB actions for the OU, and service control policies are evaluated before IAM identity policies. Because a deny in an SCP always takes precedence over an allow in an IAM policy, the user's PutItem call will be denied even if the attached IAM policy grants it. This is the correct outcome under AWS's policy evaluation model.

Why this answer

In AWS Organizations, Service Control Policies (SCPs) define the maximum permissions for accounts in an OU. An explicit Deny in an SCP overrides any Allow in IAM policies. Since the SCP denies all DynamoDB actions, the user cannot perform PutItem regardless of the IAM policy allowing it.

Exam trap

The trap is assuming that an IAM Allow can override an SCP Deny—candidates must remember that SCPs are guardrails and explicit denies in SCPs always win over IAM allows.

How to eliminate wrong answers

Option A is wrong because IAM policy allows are not effective if an SCP explicitly denies the action—SCPs take precedence. Option C is wrong because SCPs apply to all accounts in the OU, not just the root account; they affect all IAM users and roles in member accounts. Option D is wrong because SCPs do not require an explicit allow to permit actions; they only filter permissions.

An implicit deny in SCPs does not block actions if IAM allows them, but an explicit deny always blocks.

61
Multi-Selectmedium

Which TWO of the following are valid ways to grant an IAM user permissions to access an S3 bucket? (Choose 2.)

Select 2 answers
A.Assign an instance profile to the user.
B.Create a VPC endpoint policy.
C.Attach an IAM policy to the user.
D.Add the user to an IAM group with a policy.
E.Use an SCP to allow access.
AnswersC, D

An identity-based IAM policy attached directly to the user grants that user the specified S3 actions on the bucket. This is a standard, valid mechanism for granting an IAM user access, independent of any bucket policy or group membership.

Why this answer

Option C is correct because attaching an IAM identity-based policy directly to the user grants that user the specified S3 permissions, which is the standard way to authorize an IAM principal. Option D is correct because adding the user to an IAM group that has an S3 policy attached means the user inherits those permissions through group membership, another standard identity-based authorization method. Option A is incorrect because an instance profile is a container for an IAM role used by EC2 instances (and similar compute), not a mechanism for granting permissions to an IAM user.

Option B is incorrect because a VPC endpoint policy controls which principals can access the service through that endpoint; it does not grant an IAM user permissions to an S3 bucket. Option E is incorrect because an SCP sets the maximum permissions boundary for accounts in an AWS Organization; it only restricts permissions and never grants access on its own.

Exam trap

The trap here is that candidates often confuse identity-based policies (attached to users/groups/roles) with resource-based policies (like bucket policies) or other access control mechanisms (like SCPs or VPC endpoint policies), leading them to select options that do not directly grant permissions to an IAM user.

62
MCQeasy

An IAM policy attached to a user contains the above statements. The user attempts to download an object from 'example-bucket/confidential/report.pdf'. What is the result?

A.The download fails because the user is not an administrator.
B.The download succeeds because the user can access other objects.
C.The download succeeds because the first statement allows GetObject.
D.The download fails because the deny statement applies to the object.
AnswerD

The Deny statement's resource element is scoped to the exact ARN of the requested object, so it matches this specific GetObject call. In IAM's evaluation logic, an explicit Deny that matches the action and resource is an absolute veto: it overrides all Allow statements and default-deny is not even reached. Consequently, the download fails with AccessDenied because the request is explicitly denied, not because of any other condition or lack of permission.

Why this answer

The explicit Deny statement in the IAM policy takes precedence over any Allow statement, so even though the first statement allows s3:GetObject, the deny on the confidential prefix blocks the download. AWS evaluates all applicable policies and any explicit Deny wins. Therefore the download fails because the deny statement applies to the object.

Exam trap

SCS-C02 often tests the misconception that an Allow statement guarantees access, when the correct rule is that any explicit Deny in any applicable policy overrides all Allows.

How to eliminate wrong answers

Option A is wrong because the failure is not due to lack of administrator privileges; IAM evaluation is based on the specific actions and resources in the policy, not on admin status. Option B is wrong because access to other objects is irrelevant — IAM evaluates each request against the specific resource ARN, and the deny targets the confidential prefix. Option C is wrong because it ignores the explicit Deny, which overrides the Allow in AWS IAM policy evaluation logic.

63
MCQeasy

A developer is trying to use the AWS CLI to list objects in an S3 bucket but receives an AccessDenied error. The developer has an IAM user with a policy that allows s3:ListBucket on the bucket. What could be causing the error?

A.The developer has not enabled MFA on their IAM user.
B.The S3 bucket has a bucket policy that denies access to the developer's IAM user.
C.The S3 bucket does not exist in the same AWS region as the CLI is configured.
D.The IAM policy is attached to a group, not directly to the user.
AnswerB

An explicit deny statement in a bucket policy always overrides any allow granted by an IAM policy, regardless of how specific or broad that allow is. Here, even if the developer's IAM user is explicitly allowed `s3:ListBucket` by an identity-based policy, a bucket policy that contains a matching `Effect: "Deny"` for that principal (or a deny condition that matches the user) will make the request fail with AccessDenied. This is the only option that explains a denied request despite valid credentials and an otherwise permissive IAM setup.

Why this answer

S3 access decisions are evaluated by combining IAM identity-based policies with bucket policies, and an explicit Deny in either location always wins. Even though the developer's IAM policy grants s3:ListBucket, a bucket policy that explicitly denies the user's principal overrides that Allow. This is the classic 'explicit deny beats allow' rule in AWS's policy evaluation logic.

Exam trap

SCS-C02 often tests the misconception that an IAM Allow is sufficient for S3 access, when in fact an explicit Deny in a bucket policy, SCP, or permission boundary silently overrides it.

How to eliminate wrong answers

Option A is wrong because MFA is not required for s3:ListBucket by default; MFA is only enforced if a policy explicitly includes the aws:MultiFactorAuthPresent condition, and nothing in the scenario indicates that. Option C is wrong because S3 bucket names are globally unique and the CLI automatically resolves the correct regional endpoint; a region mismatch produces a redirect or NoSuchBucket error, not AccessDenied. Option D is wrong because IAM policies attached to a group are inherited by group members, so attaching the policy to a group instead of directly to the user still grants the permission.

64
MCQhard

A company has an IAM policy that allows s3:GetObject on all buckets. However, a specific S3 bucket policy explicitly denies s3:GetObject to all principals. An IAM user with the IAM policy tries to read an object from that bucket. What is the result?

A.The request is allowed because the IAM policy is more specific.
B.The request is allowed because the IAM policy allows the action.
C.The request is denied because the bucket policy applies only to IAM users.
D.The request is denied because the explicit deny in the bucket policy overrides the allow in the IAM policy.
AnswerD

This is correct because AWS IAM policy evaluation uses a single decision tree in which any explicit deny overrides all allow statements, regardless of where those allows originate. The IAM policy allows s3:GetObject, but the bucket policy contains an explicit deny for the same action and principal. That explicit deny takes precedence, causing the request to be denied. This fundamental rule ensures that explicit deny statements are always authoritative over allows.

Why this answer

D is correct because AWS IAM policy evaluation logic follows an explicit deny override: any explicit deny in any applicable policy (resource-based or identity-based) overrides any allow. The S3 bucket policy explicitly denies s3:GetObject to all principals, so even though the IAM policy allows the action, the explicit deny takes precedence, resulting in a denied request.

Exam trap

The trap here is that candidates often assume an identity-based allow (IAM policy) can override a resource-based deny (bucket policy), but AWS explicitly prioritizes denies over allows across all policy types.

How to eliminate wrong answers

Option A is wrong because AWS does not use a 'more specific' rule between policies; explicit deny always overrides allow regardless of specificity. Option B is wrong because the IAM policy allow is overridden by the explicit deny in the bucket policy; an allow alone does not guarantee access when a deny exists. Option C is wrong because bucket policies apply to all principals, not just IAM users; the explicit deny in the bucket policy applies to the IAM user as a principal.

65
MCQmedium

An organization has a production AWS account and a development AWS account. Developers need to access the production account from the development account using IAM roles. What is the MOST secure way to set this up?

A.Create an IAM role in the production account with a trust policy allowing the development account to assume it.
B.Create IAM users in the production account and share access keys with developers.
C.Establish a VPN connection between the accounts and use directory credentials.
D.Create the same IAM users in both accounts with identical permissions.
AnswerA

This is the correct approach because it uses an IAM role with a trust policy that explicitly delegates the ability to assume the role to the development account. When the development account calls sts:AssumeRole, it receives temporary, automatically rotating credentials scoped to the permissions policy attached to the role, so no long-term access keys are stored or shared. The trust policy should also include a condition such as aws:SourceAccount to protect against the confused deputy problem and ensure only the intended development account can request the role.

Why this answer

It uses cross-account IAM roles, allowing developers in the development account to assume a role in the production account using AWS Security Token Service (STS). This provides temporary, least-privilege credentials without sharing long-term access keys. Option B is insecure because sharing access keys creates long-term credentials that are hard to rotate and manage.

Option C is incorrect: a VPN provides network connectivity but does not grant IAM access. Option D is incorrect because IAM users are account-specific; duplicating users across accounts does not enable cross-account access.

66
MCQeasy

An organization wants to use AWS Organizations to centrally manage permissions for multiple accounts. Which IAM feature is used to grant cross-account access within the organization?

A.IAM roles
B.Service control policies (SCPs)
C.Resource-based policies
D.IAM groups
AnswerA

IAM roles are the correct mechanism because they support cross-account trust relationships: the organization can configure a role in a target account with a trust policy allowing principals from a central account to assume it. When a user or service in the central account calls sts:AssumeRole, AWS STS returns temporary credentials scoped to the role's permissions policy, enabling centrally governed access across accounts. This is the standard way to grant access to AWS accounts, and it can be combined with AWS Organizations' central management for auditing and policy enforcement.

Why this answer

IAM roles are the standard mechanism for granting cross-account access within AWS Organizations. A role in the target (trusting) account defines a trust policy that names principals in other accounts as trusted entities, and those principals call sts:AssumeRole to obtain temporary credentials scoped to the role's permissions policy. This avoids creating duplicate IAM users in every account and is the recommended pattern for centralized, auditable cross-account access.

Exam trap

SCS-C02 often tests the misconception that SCPs grant permissions — candidates confuse SCPs (which only limit maximum permissions) with IAM roles (which actually grant cross-account access).

How to eliminate wrong answers

Option B is wrong because SCPs only define the maximum permissions boundary for accounts in an organization — they restrict what identities can do but do not themselves grant any permissions or establish cross-account trust. Option C is wrong because resource-based policies (e.g., S3 bucket policies) can grant cross-account access to specific resources, but they are resource-specific and not the general IAM feature used to grant cross-account access across an organization. Option D is wrong because IAM groups are containers for IAM users within a single account and cannot span accounts or be referenced in a trust policy.

67
MCQeasy

An application running on an EC2 instance needs to read from an S3 bucket. What is the BEST practice for granting permissions to the EC2 instance?

A.Store AWS access keys in the application code.
B.Create an IAM user and give access keys to the developer.
C.Use an IAM role and attach it to the EC2 instance profile.
D.Use the root account credentials.
AnswerC

Attaching an IAM role to the EC2 instance profile allows the instance to retrieve temporary security credentials from the instance metadata service (IMDSv2). The SDK automatically calls the Amazon EC2 metadata endpoint (http://169.254.169.254) to obtain an access key, secret key, and session token, which are then used for API requests. These credentials are temporary, automatically rotated, and carry only the permissions defined by the role's policy, avoiding any embedded secrets.

Why this answer

The best practice is to use an IAM role attached to the EC2 instance via an instance profile. This provides temporary, automatically rotated credentials to the instance, eliminating the need to hardcode or distribute long-term access keys. The instance profile allows the EC2 instance to assume the role and obtain credentials from the Instance Metadata Service (IMDS), which the AWS SDK and CLI use automatically.

This approach follows the principle of least privilege and is the most secure and manageable method for granting AWS permissions to EC2 instances.

Exam trap

SCS-C02 often tests the misconception that IAM user access keys are acceptable for EC2 instances, but the exam expects you to recognize that IAM roles with instance profiles are the only secure, best-practice solution for granting permissions to EC2.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys in application code is a severe security risk—keys can be exposed in source control, logs, or reverse engineering, and they are long-term credentials that are difficult to rotate. Option B is wrong because creating an IAM user and giving access keys to a developer violates best practices: it uses long-term credentials, lacks automatic rotation, and ties permissions to a human user rather than the instance, increasing the risk of credential leakage and making auditing harder. Option D is wrong because using root account credentials is extremely dangerous—the root account has unrestricted access to all resources and billing, and AWS strongly recommends never using root for programmatic access; it also cannot be restricted by IAM policies.

68
MCQeasy

Which IAM feature allows you to grant temporary, limited-privilege credentials for a specific role?

A.Resource-based policies
B.IAM roles
C.AWS STS
D.Service control policies
AnswerC

AWS STS is the service that issues temporary, limited-privilege credentials through APIs like GetSessionToken, AssumeRole, and GetFederationToken. These credentials consist of an access key ID, a secret access key, and a session token, and they automatically expire after a configurable duration, ranging from 15 minutes to 36 hours depending on the API used. This reduces the risk of long-term credential exposure and is the correct IAM feature that directly grants temporary credentials.

Why this answer

AWS STS (Security Token Service) is the service that provides temporary, limited-privilege credentials for IAM roles or federated users. When you assume a role, STS issues temporary security credentials that can be used to access AWS resources. This is the core mechanism for granting temporary access.

Exam trap

SCS-C02 often tests the distinction between IAM roles and STS, where candidates might think that IAM roles themselves provide credentials, but actually STS is the service that issues the temporary credentials.

How to eliminate wrong answers

Option A is wrong because resource-based policies are attached to resources (like S3 buckets) and define who can access them, but they do not grant temporary credentials. Option B is wrong because IAM roles are an identity that can be assumed, but the actual temporary credentials are issued by STS. Option D is wrong because Service Control Policies are used in AWS Organizations to set permission boundaries, not to grant temporary credentials.

69
MCQeasy

A developer needs to run an application on an EC2 instance that accesses an S3 bucket. What is the best practice for granting permissions?

A.Use an SCP to allow S3 access for the instance.
B.Create a bucket policy that grants access to the instance ID.
C.Store AWS access keys on the instance and use them in the application.
D.Create an IAM role with S3 access and attach it to the EC2 instance profile.
AnswerD

This is the correct approach because an IAM role attached to an EC2 instance profile securely provides the instance with temporary credentials through the instance metadata service. The role enforces least-privilege permissions for S3, automatically rotates credentials, and eliminates the need to embed long-term keys, aligning with AWS security best practices and following the principle of granting only the required access.

Why this answer

The correct answer is D because attaching an IAM role to an EC2 instance profile provides temporary, automatically rotated credentials to the instance, eliminating the need to hardcode or manage long-term access keys. This follows the AWS best practice of using IAM roles for EC2 to grant least-privilege permissions to AWS services like S3. The instance profile acts as a container for the role and allows the EC2 instance to assume it, with credentials delivered via the Instance Metadata Service (IMDS).

Exam trap

SCS-C02 often tests the misconception that SCPs or bucket policies can directly grant permissions to EC2 instances, or that long-term access keys are acceptable for instance-based access, when the best practice is always to use IAM roles for EC2.

How to eliminate wrong answers

Option A is wrong because SCPs (Service Control Policies) are used at the AWS Organizations level to set permission guardrails, not to grant permissions to EC2 instances; they only limit what IAM principals can do and cannot grant access. Option B is wrong because a bucket policy grants access to IAM principals (users, roles, accounts) or services, not to an EC2 instance ID; instance IDs are not valid principals in IAM policies. Option C is wrong because storing AWS access keys on an instance is a security anti-pattern that risks key leakage and does not follow best practices for credential management; keys should be rotated and never embedded in code or instances.

70
MCQeasy

A security engineer is reviewing an IAM policy that grants permissions to an IAM user. The policy includes the following statement: { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::example-bucket/*" }. The engineer wants to ensure that the user can only access objects in the bucket when the request originates from a specific VPC endpoint. Which additional element should the engineer add to the policy?

A.A condition that checks aws:RequestedRegion against the region of the VPC endpoint.
B.A condition that checks aws:PrincipalOrgID against the organization ID.
C.A condition that checks aws:SourceIp against the VPC CIDR range.
D.A condition that checks aws:SourceVpce against the VPC endpoint ID.
AnswerD

The aws:SourceVpce condition key can be used to restrict access to requests that come through a specific VPC endpoint. Adding this condition ensures that the user can only access objects when the request originates from that endpoint, meeting the requirement to limit access to a specific VPC endpoint.

Why this answer

The aws:SourceVpce condition key is used to allow or deny access based on the VPC endpoint through which the request is made. By including this condition in the IAM policy, the engineer ensures that only requests routed through the specified VPC endpoint can access the S3 objects. This is a common pattern for restricting access to private network paths.

Exam trap

The trap here is confusing network-based conditions like aws:SourceIp with endpoint-specific conditions, when only aws:SourceVpce can precisely limit access to a particular VPC endpoint.

71
MCQeasy

A company wants to allow users to assume a role in another AWS account to access a specific S3 bucket. What must be configured?

A.A trust policy on the IAM role that allows the user's account to assume the role.
B.An S3 bucket policy that allows the user to access the bucket.
C.An IAM role with a trust policy allowing the user's account and a bucket policy granting the role access to the bucket.
D.A resource-based policy on the S3 bucket that allows the user's account.
AnswerC

This is the complete cross-account access solution: the role's trust policy allows the user's account to assume the role, and the bucket policy grants the role's ARN explicit permission to perform S3 actions. The user calls sts:AssumeRole and receives temporary credentials scoped to the role, then uses those credentials to access the bucket; the bucket policy recognizes the assumed-role principal. Both policies are necessary because the trust policy does not confer resource permissions, and the bucket policy does not grant the ability to assume the role.

Why this answer

Cross-account role assumption requires two coordinated policies: a trust policy on the IAM role in the target account that names the user's account (or principal) as a trusted entity, and a resource-based policy (bucket policy) in the target account granting the role access to the S3 bucket. Both are necessary because the trust policy authorizes the AssumeRole call, while the bucket policy authorizes the S3 actions once the role is assumed.

Exam trap

SCS-C02 often tests the misconception that a trust policy or a bucket policy alone is sufficient, when cross-account role assumption actually requires both the trust relationship and the resource permission to be in place.

How to eliminate wrong answers

Option A is wrong because a trust policy alone only allows the AssumeRole call; without a bucket policy granting the role S3 permissions, the assumed role cannot actually read the bucket. Option B is wrong because a bucket policy alone does not establish the trust relationship needed for the user to assume a role in the other account. Option D is wrong because a resource-based policy on the bucket that grants the user's account directly does not involve role assumption and does not satisfy the requirement to 'assume a role in another AWS account.'

72
MCQmedium

An administrator wants to audit all IAM actions in the account. Which AWS service should be used?

A.AWS Config
B.Amazon GuardDuty
C.AWS CloudTrail
D.Amazon CloudWatch
AnswerC

AWS CloudTrail records API activity across the account, capturing every IAM action as a management event with caller identity, timestamp and source IP. This satisfies the requirement to audit all IAM actions, since CloudTrail logs control-plane operations by default. CloudWatch, Config and Trusted Advisor do not provide this comprehensive API audit trail.

Why this answer

AWS CloudTrail records API activity, including all IAM actions. AWS Config tracks resource configuration changes, not API actions. Amazon GuardDuty is a threat detection service.

Amazon CloudWatch monitors metrics and logs, but does not record API calls.

73
Multi-Selecthard

A security engineer is designing a permissions boundary for an IAM role used by an EC2 instance. The role must be able to read from an S3 bucket (my-bucket) and write to CloudWatch Logs. Which THREE conditions must be met for the role to have effective permissions? (Choose THREE.)

Select 3 answers
A.The EC2 instance must have an instance profile attached.
B.The effective permissions are the intersection of the boundary and identity-based policies.
C.The identity-based policy attached to the role must allow the required actions.
D.The permissions boundary policy must allow the required actions.
E.The S3 bucket policy must explicitly allow the role.
AnswersB, C, D

Effective permissions for any principal are always the intersection of all applicable policies: the permissions boundary acts as a ceiling, and the identity-based policy (e.g., attached to the role) acts as the grant. The IAM engine evaluates both, and an action is permitted only if it is allowed by the identity-based policy, not denied by the boundary, and not denied by any other policy (like a service control policy or resource policy). This intersection model is the fundamental logic of IAM permissions boundaries: the boundary limits the maximum permissions, but the identity policy must still explicitly grant the action within that limit.

Why this answer

Option B is correct because AWS evaluates a permissions boundary as a filter: the role's effective permissions are the intersection of what the identity-based policy grants and what the boundary allows, so an action must be permitted by both. Option C is correct because the identity-based policy attached to the role is the primary grant of permissions; without it allowing s3:GetObject on my-bucket and logs:CreateLogStream/logs:PutLogEvents, the role has no permissions regardless of the boundary. Option D is correct because the permissions boundary must also allow those same required actions, since any action not permitted by the boundary is denied even if the identity-based policy allows it.

Option A is not required for effective permissions because an instance profile is merely the container that delivers a role's temporary credentials to EC2, not a condition that grants or restricts the role's permissions. Option E is not required because a bucket policy is only needed when cross-account access or explicit resource-based grants are involved; for same-account access, the identity-based policy plus boundary is sufficient.

Exam trap

SCS-C02 often tests the misconception that a permissions boundary grants permissions, when in fact it only limits them — candidates incorrectly select the boundary as sufficient on its own.

74
MCQeasy

An IAM policy allows the iam:PassRole action for a specific role only when the role is passed to EC2. A developer tries to launch an EC2 instance with this role, but fails. What is the most likely missing permission?

A.The developer does not have ec2:RunInstances permission.
B.The developer needs to create the role first.
C.The developer does not have iam:PassRole permission for the role.
D.The condition in the policy is incorrect; it should use 'ec2.amazonaws.com' as the service.
AnswerA

Launching an EC2 instance is an ec2:RunInstances API call, and IAM requires a separate, explicit authorization for that action. A policy that grants iam:PassRole only authorizes the developer to attach a pre-existing role to a resource; it does not authorize creating or starting the instance itself. Without ec2:RunInstances permission, AWS denies the request even though the PassRole policy is valid, so this is the correct reason for the failure.

Why this answer

iam:PassRole only authorizes the principal to hand a role to a service; it does not authorize the service action itself. To launch an EC2 instance, the developer must also have ec2:RunInstances in their identity-based policy. The scenario states the PassRole condition is correctly scoped to EC2, so the failure is most likely the absence of the EC2 launch permission.

Without ec2:RunInstances, the API call is denied before PassRole is even evaluated.

Exam trap

SCS-C02 often tests the misconception that iam:PassRole alone is sufficient to use a role with a service — candidates forget that the service action (e.g., ec2:RunInstances) must also be allowed.

How to eliminate wrong answers

Option B is wrong because the role already exists (the policy references a specific role), and creating a role is not required to launch an instance with it. Option C is wrong because the question states the policy allows iam:PassRole for the role when passed to EC2 — so the permission is present and correctly conditioned. Option D is wrong because the condition for passing a role to EC2 uses the service principal 'ec2.amazonaws.com' in the iam:PassedToService condition key, which is exactly what the scenario describes; the condition is not the problem.

75
MCQeasy

A developer needs to allow a Lambda function to write logs to CloudWatch Logs. What is the MINIMUM IAM policy that should be attached to the Lambda execution role?

A.{"Effect":"Allow","Action":["logs:CreateLogGroup","logs:CreateLogStream","logs:PutLogEvents"],"Resource":"*"}
B.{"Effect":"Allow","Action":"logs:PutLogEvents","Resource":"arn:aws:logs:us-east-1:123456789012:log-group:my-log-group:*"}
C.{"Effect":"Allow","Action":"logs:*","Resource":"*"}
D.{"Effect":"Allow","Action":["logs:DescribeLogGroups","logs:DescribeLogStreams"],"Resource":"*"}
AnswerA

CloudWatch Logs requires exactly these three log actions for a Lambda function to create its log group, stream and write events. Omitting any action causes logging to fail, so this is the minimum viable set.

Why this answer

The minimum policy for a Lambda function to write logs to CloudWatch Logs must include logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Lambda creates the log group and stream on first invocation, so all three actions are required. Resource '*' is acceptable because the log group name is not known in advance and Lambda needs to create it dynamically.

Exam trap

SCS-C02 often tests whether candidates know that Lambda requires CreateLogGroup and CreateLogStream in addition to PutLogEvents — many pick only PutLogEvents and miss the creation actions.

How to eliminate wrong answers

Option B is wrong because it only allows logs:PutLogEvents on a specific pre-existing log group — Lambda cannot create the log group or stream, so the first invocation fails. Option C is wrong because logs:* grants far more than the minimum, violating least privilege. Option D is wrong because DescribeLogGroups and DescribeLogStreams are read-only actions that do not allow writing log events.

Page 1 of 3 · 151 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Identity and Access Management questions.