Courseiva

SCS-C02 · topic practice

Identity and Access Management practice questions

This domain covers how AWS evaluates every request: IAM users, groups, roles, and policies, plus resource-based policies, permission boundaries, SCPs, and identity federation. You must read policy JSON and predict the effective permission, including explicit denies, trust policies, and cross-account access. Expect scenario questions on least-privilege design and credential handling.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Identity and Access Management

What the exam tests

What to know about Identity and Access Management

Given a scenario, determine the effective permissions by combining identity policies, resource policies, boundaries, SCPs, and conditions, then choose the least-privilege option. The single most important thing: an explicit Deny always wins, and roles with temporary credentials beat embedded access keys.

Reading IAM identity-based and resource-based policy JSON to determine effective allow or deny

Distinguishing IAM roles and STS AssumeRole from long-term access keys for AWS service access

Applying permissions boundaries, SCPs, and session policies as permission guardrails

Using iam:ChangePassword, iam:GetUser, and MFA conditions for self-service and console access

Watch out for

Common Identity and Access Management exam traps

  • ▸Forgetting that an explicit Deny in any applicable policy overrides every Allow, including administrator access.
  • ▸Assuming a resource-based policy alone grants access without checking the identity's own permissions or account trust.
  • ▸Confusing permissions boundaries with SCPs: boundaries limit identities, SCPs limit accounts in Organizations.

Practice set

Identity and Access Management questions

20 questions · select your answer, then reveal the explanation

An IAM policy includes the following condition: "StringNotEquals": {"aws:SourceArn": "arn:aws:ec2:us-east-1:123456789012:instance/*"}. What is the effect of this condition when attached to an IAM role?

An IAM user receives an 'AccessDenied' error when trying to list objects in an S3 bucket. The user has the following policy attached: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::example-bucket"}]}. What is the most likely reason?

Which TWO are valid ways to authenticate to AWS for API calls? (Choose two.)

Refer to the exhibit. A security engineer runs the command above. Which of the following is true about the role MyRole?

Network Topology
$ aws iam get-rolerole-name MyRoleRefer to the exhibit."Role": {"Path": "/","RoleName": "MyRole","Arn": "arn:aws:iam::123456789012:role/MyRole","AssumeRolePolicyDocument": {"Version": "2012-10-17","Statement": ["Effect": "Allow","Principal": {"Service": "ec2.amazonaws.com"},"Action": "sts:AssumeRole"

A company has a multi-account AWS Organization with three accounts: Management, Development, and Production. The Security team uses the Management account to manage IAM policies centrally. They have created a service control policy (SCP) named 'RestrictRootAccess' that denies all actions for the root user in all accounts. The SCP is attached to the root organizational unit. The Development account has an IAM role 'DevAdmin' with full administrator access via an IAM policy. The role's trust policy allows the Management account's 'SecurityAudit' role to assume it. A security engineer in the Management account assumes the 'SecurityAudit' role and then tries to assume the 'DevAdmin' role in the Development account. The assumption fails with an 'AccessDenied' error. What is the most likely cause?

A developer is trying to upload an object to an S3 bucket named 'my-bucket' using the AWS CLI. The developer has an IAM user with a policy that includes 's3:PutObject' for 'arn:aws:s3:::my-bucket/*'. However, the upload fails with an 'Access Denied' error. The bucket policy is set to allow all principals from the same AWS account to perform 's3:PutObject'. What is the most likely cause of this failure?

An IAM policy is attached to a user. The user is trying to change their own password in the IAM console but receives an 'Access Denied' error. The user has an MFA device configured and is logged in with MFA. Why is the password change failing?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": "*",
      "Resource": "*",
      "Condition": {
        "BoolIfExists": {
          "aws:MultiFactorAuthPresent": "false"
        }
      }
    },
    {
      "Effect": "Allow",
      "Action": "iam:ChangePassword",
      "Resource": "*"
    }
  ]
}

A security engineer is designing a solution to allow an external auditor to access logs in an S3 bucket in the company's AWS account. The auditor does not have an AWS account. The engineer needs to grant read-only access to the specific bucket for a limited time. Which TWO actions should the engineer take? (Choose two.)

Drag and drop the steps to configure AWS CloudTrail for logging across all regions and accounts in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each AWS KMS key type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Managed by AWS for use with specific services

Managed by customer with full control

Used internally by AWS, not visible to customers

Key store backed by AWS CloudHSM

Match each AWS CloudHSM feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Hardware security module

Cryptographic token interface standard

Java Cryptography Extension provider

Security standard for cryptographic modules

A security engineer notices that an IAM user has permissions that are not explicitly granted through any policy. The engineer suspects that the user might have inherited permissions from a group or role. Which IAM feature should the engineer use to identify the source of these permissions?

An organization wants to enforce that all IAM users use MFA. The security team creates an IAM policy that denies all actions unless MFA is present. However, some users report they cannot even change their own password to enable MFA. What should the security team do to resolve this?

Which THREE are valid ways to grant cross-account access to an S3 bucket? (Choose three.)

A security engineer is designing a cross-account access solution. An IAM role in Account A needs to be assumed by users from Account B. Which two components are required?

An IAM user needs to rotate their own access keys. Which IAM policy action should be allowed?

A security engineer notices that an IAM role for an EC2 instance has a policy that allows s3:PutObject on a bucket. However, the application reports access denied when trying to upload. The bucket policy does not explicitly deny access. What is a likely cause?

A security engineer needs to ensure that an IAM role can be assumed only from a specific VPC. Which IAM policy condition key should be used?

Which TWO of the following are valid IAM policy condition keys? (Choose TWO.)

A security engineer attaches this policy to an IAM user. The user tries to download an object from the bucket from an IP address 10.1.0.5. What will happen?

Exhibit

Refer to the exhibit. IAM policy JSON:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.0.0.0/16"
        }
      }
    }
  ]
}

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Identity and Access Management sessions

Start a Identity and Access Management only practice session

Every question in these sessions is drawn from the Identity and Access Management domain — nothing else.

Related practice questions

Related SCS-C02 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SCS-C02 exam test about Identity and Access Management?
Given a scenario, determine the effective permissions by combining identity policies, resource policies, boundaries, SCPs, and conditions, then choose the least-privilege option. The single most important thing: an explicit Deny always wins, and roles with temporary credentials beat embedded access keys.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Identity and Access Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Identity and Access Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SCS-C02 topics?
Use the topic links above to move to related areas, or go back to the SCS-C02 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SCS-C02 exam covers. They are not copied from any real exam or dump site.