SCS-C02 Identity and Access Management Practice Question
Which IAM entity can be used to grant temporary access to AWS resources for users from a different AWS account?
⚠ Common exam trap
Watch out — candidates often confuse an IAM policy with an IAM role, thinking that attaching a policy directly to an external user grants access, but policies alone cannot be assumed and do not generate temporary credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM role
An IAM role is the correct entity because it is specifically designed to grant temporary, cross-account access to AWS resources. When a user from a different AWS account assumes a role, AWS STS (Security Token Service) issues temporary security credentials (access key, secret key, and session token) that are valid for a configurable duration (default 1 hour, max 12 hours). This avoids the need to create permanent IAM users or share long-term credentials across accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IAM group
Why it's wrong here
IAM groups are not security principals that can be assumed or issued temporary credentials. A group is a logical container that groups IAM users to simplify permission management; when a user in the group authenticates, they still use their own long-term credentials. Temporary access requires assuming an IAM role via sts:AssumeRole, not being a member of a group.
- ✓
IAM role
Why this is correct
An IAM role is the correct entity for granting temporary access because it is designed to be assumed. When a principal assumes a role, AWS STS returns temporary security credentials with a limited lifetime, governed by the role's trust policy and permissions policy. This is the standard mechanism for federated access, cross-account access, and EC2 instance profiles.
- ✗
IAM policy
Why it's wrong here
An IAM policy is not an identity or security principal, so it cannot be assumed to receive any credentials. Policies are JSON documents that define permissions and are attached to identities or resources; they do not have their own trust relationships or generate temporary session tokens. Only roles or other STS endpoints can issue temporary access, never a policy itself.
- ✗
IAM user
Why it's wrong here
An IAM user is a persistent identity with long-term credentials (password and access keys) used for day-to-day authentication. While you can call STS GetSessionToken with a user's credentials to get short-lived tokens, the user entity itself does not inherently provide temporary access in the way a role does. For true temporary access across trust boundaries, you define and assume an IAM role.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.