SCS-C02 Identity and Access Management Practice Question
Which IAM feature allows you to grant temporary, limited-privilege credentials for a specific role?
⚠ Common exam trap
SCS-C02 often tests the distinction between IAM roles and STS, where candidates might think that IAM roles themselves provide credentials, but actually STS is the service that issues the temporary credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS STS
AWS STS (Security Token Service) is the service that provides temporary, limited-privilege credentials for IAM roles or federated users. When you assume a role, STS issues temporary security credentials that can be used to access AWS resources. This is the core mechanism for granting temporary access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource-based policies
Why it's wrong here
Resource-based policies are JSON documents attached to a specific resource, such as an S3 bucket or a KMS key, to specify which principals are allowed to access that resource. They do not generate or provide temporary credentials; they only define authorization rules that are evaluated after a request has already been authenticated using credentials obtained from STS. Resource-based policies can be used in conjunction with IAM roles for cross-account access, but the role assumption through STS is still required to obtain credentials.
- ✗
IAM roles
Why it's wrong here
IAM roles are not a credential-issuing service; they are permission containers that define what actions a principal can perform on AWS resources. When a principal assumes a role, the actual temporary credentials are returned by the AWS Security Token Service (STS) via the AssumeRole API call. Without STS, a role is simply a policy entity with no ability to authenticate requests, so selecting roles would confuse authorization policies with the credential issuance mechanism.
- ✓
AWS STS
Why this is correct
AWS STS is the service that issues temporary, limited-privilege credentials through APIs like GetSessionToken, AssumeRole, and GetFederationToken. These credentials consist of an access key ID, a secret access key, and a session token, and they automatically expire after a configurable duration, ranging from 15 minutes to 36 hours depending on the API used. This reduces the risk of long-term credential exposure and is the correct IAM feature that directly grants temporary credentials.
- ✗
Service control policies
Why it's wrong here
Service control policies (SCPs) are used in AWS Organizations to centrally limit the maximum permissions available to IAM users and roles in member accounts. SCPs do not grant permissions, and they do not issue temporary credentials; they only act as a guardrail that constrains what can be performed even if STS issues a session token. SCPs affect the evaluation of all principal-based and resource-based policies within an account, but they are never a source of credentials themselves.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.