Courseiva

SCS-C02 Identity and Access Management Practice Question

Which IAM entity can be used to grant temporary access to AWS resources for users from a different AWS account?

⚠ Common exam trap

Watch out — candidates often confuse an IAM policy with an IAM role, thinking that attaching a policy directly to an external user grants access, but policies alone cannot be assumed and do not generate temporary credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IAM role

An IAM role is the correct entity because it is specifically designed to grant temporary, cross-account access to AWS resources. When a user from a different AWS account assumes a role, AWS STS (Security Token Service) issues temporary security credentials (access key, secret key, and session token) that are valid for a configurable duration (default 1 hour, max 12 hours). This avoids the need to create permanent IAM users or share long-term credentials across accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IAM group

    Why it's wrong here

    IAM groups are not security principals that can be assumed or issued temporary credentials. A group is a logical container that groups IAM users to simplify permission management; when a user in the group authenticates, they still use their own long-term credentials. Temporary access requires assuming an IAM role via sts:AssumeRole, not being a member of a group.

  • ✓

    IAM role

    Why this is correct

    An IAM role is the correct entity for granting temporary access because it is designed to be assumed. When a principal assumes a role, AWS STS returns temporary security credentials with a limited lifetime, governed by the role's trust policy and permissions policy. This is the standard mechanism for federated access, cross-account access, and EC2 instance profiles.

  • ✗

    IAM policy

    Why it's wrong here

    An IAM policy is not an identity or security principal, so it cannot be assumed to receive any credentials. Policies are JSON documents that define permissions and are attached to identities or resources; they do not have their own trust relationships or generate temporary session tokens. Only roles or other STS endpoints can issue temporary access, never a policy itself.

  • ✗

    IAM user

    Why it's wrong here

    An IAM user is a persistent identity with long-term credentials (password and access keys) used for day-to-day authentication. While you can call STS GetSessionToken with a user's credentials to get short-lived tokens, the user entity itself does not inherently provide temporary access in the way a role does. For true temporary access across trust boundaries, you define and assume an IAM role.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.