Courseiva

IAM PassRole — ARN Mismatch Error Troubleshooting

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "iam:PassRole",
      "Resource": "arn:aws:iam::123456789012:role/ec2-full-access"
    },
    {
      "Effect": "Allow",
      "Action": "ec2:RunInstances",
      "Resource": "*"
    }
  ]
}

An IAM policy allows a user to pass a specific role and launch EC2 instances. The user tries to launch an EC2 instance with the role 'ec2-full-access' but receives an error: 'You are not authorized to perform iam:PassRole'. What is the MOST likely cause?

Quick Answer

The answer is an ARN mismatch between the role the user is trying to pass and the role specified in the IAM policy. This error occurs because the `iam:PassRole` permission is evaluated against the exact Amazon Resource Name (ARN) of the role being passed; if the user attempts to pass `ec2-full-access` but the policy only grants `PassRole` on a different ARN—even a minor difference in the role name, path, or account ID—the API call fails with the "not authorized" error. On the AWS Certified Security Specialty SCS-C02 exam, this scenario tests your understanding that `PassRole` is a separate, resource-level permission from `RunInstances`, and that wildcards in the `ec2:RunInstances` action do not extend to the role ARN. A common trap is assuming the error is about missing EC2 permissions or a missing role, when in fact the role exists but the ARN does not match. Memory tip: "PassRole is picky—exact ARN or it’s a nope."

⚠ Common exam trap

SCS-C02 often tests the misconception that iam:PassRole permission is granted based on role name alone, but the exam expects you to know that the exact ARN, including path and account ID, must match the policy's Resource element.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user is attempting to pass a role with an ARN that does not exactly match the one in the policy

The error 'You are not authorized to perform iam:PassRole' indicates that the iam:PassRole permission is being denied. In IAM policies, the Resource element for iam:PassRole must specify the exact ARN of the role that can be passed. If the user attempts to pass a role whose ARN does not exactly match the ARN in the policy (e.g., due to a different path, account ID, or role name), the PassRole action is not allowed, resulting in this error. Therefore, the most likely cause is that the role ARN being passed does not match the ARN specified in the policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The role 'ec2-full-access' does not exist in the account

    Why it's wrong here

    A missing role produces a different error, typically NoSuchEntity when the role is referenced; the stated iam:PassRole denial means the role exists but the policy's Resource element does not match its ARN. It is tempting because a typo in the role name is a common cause of launch failures.

  • ✓

    The user is attempting to pass a role with an ARN that does not exactly match the one in the policy

    Why this is correct

    The iam:PassRole error occurs because the role ARN in the request does not exactly match the Resource element in the policy. IAM evaluates ARNs literally, so any mismatch in account, path, or role name denies the action despite the Allow.

  • ✗

    The policy is missing a condition key such as ec2:InstanceProfile

    Why it's wrong here

    A missing ec2:InstanceProfile condition would still surface as an iam:PassRole denial, but the stem states the policy allows passing a specific role, so the mismatch is the role's ARN in the Resource element. It is tempting because condition keys restrict which instance profiles can be attached.

  • ✗

    The user does not have permission to call ec2:RunInstances

    Why it's wrong here

    The error names iam:PassRole specifically, so ec2:RunInstances is not the failing action; the stem already grants instance launching. It is tempting because both permissions are needed for this workflow, and missing RunInstances would be correct if the error cited that action instead.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security engineer notices that an IAM role allows 'iam:PassRole' to an EC2 instance. What security risk does this present?

medium
  • ✓ A.The instance can launch new resources with a more privileged role.
  • B.The instance can modify IAM policies.
  • C.The instance can stop CloudTrail logging.
  • D.The instance can decrypt data encrypted with KMS keys.

Why A: The 'iam:PassRole' permission allows an entity to pass an IAM role to an AWS service, such as EC2. If an EC2 instance has this permission, it can launch new resources (like another EC2 instance or a Lambda function) and associate a more privileged role with that resource. This is a privilege escalation risk because the instance could effectively gain the permissions of the passed role.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.