Courseiva

SCS-C02 Identity and Access Management Practice Question

Which THREE are best practices for securing IAM in an AWS environment? (Choose THREE.)

⚠ Common exam trap

The SCS-C02 exam often tests the misconception that the root user is acceptable for daily tasks because it has full access, but the trap is that the root user lacks granular audit trails and cannot be restricted by IAM policies, making it a massive security risk for routine operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use IAM roles for applications running on EC2.

Using IAM roles for EC2 instances eliminates the need to store long-term AWS credentials (access keys) on the instance. Instead, the instance assumes the role via the EC2 metadata service, which automatically rotates temporary security credentials (via AWS STS). This follows the principle of least privilege and reduces the risk of credential leakage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use IAM roles for applications running on EC2.

    Why this is correct

    IAM roles allow EC2 instances to obtain temporary security credentials automatically through instance profiles, eliminating the need to embed long-term access keys on the instance. These temporary credentials are vended via the instance metadata service and are rotated by AWS STS, reducing the risk of leaked keys and their blast radius. Roles also let you enforce least privilege cleanly, because you can attach narrowly scoped policies to the role and update them without modifying the instance.

  • ✓

    Enable MFA for all IAM users.

    Why this is correct

    MFA adds a second authentication factor beyond a password or access key, so even if a user's password is phished or guessed, an attacker still cannot sign in without the physical MFA device. AWS recommends enabling MFA for all IAM users, especially those with console access and administrative permissions, as it mitigates the most common credential-compromise vectors. Crucially, MFA should also be enabled on the root user, because root credentials have full access to the account and cannot be scoped down.

  • ✗

    Use the AWS account root user for daily administrative tasks.

    Why it's wrong here

    The root user has permanent, unrestricted access to every resource in the account, and no IAM policy can limit its permissions, making it the highest-impact credential an attacker could steal. Using root for daily administrative tasks means any single compromised root credential grants an attacker complete account takeover, defeating the entire purpose of IAM identity separation. AWS best practice is to reserve root for a few account-level operations, such as closing the account or creating a support case, and to use IAM users or roles for everything else.

  • ✗

    Grant broad permissions to simplify management.

    Why it's wrong here

    Broad permissions, such as wildcard actions or full resource access, violate the principle of least privilege and dramatically expand the potential damage if a credential is compromised. An identity with overly permissive policies can be used by an attacker to delete data, launch expensive resources, or pivot to other services at will. Additionally, broad scopes make security audits nearly impossible, because you cannot distinguish legitimate usage from malicious activity in CloudTrail logs.

  • ✓

    Rotate IAM user access keys regularly.

    Why this is correct

    IAM access keys are long-lived credentials that remain valid indefinitely unless rotated or revoked, so periodic rotation limits the exposure window if a key is leaked. You can use the AWS credential report to identify keys that have never been used or are old, and then rotate or delete them based on the 'last used' timestamp. Although rotation is a core best practice, the more scalable strategy is to replace static keys entirely with temporary credentials from IAM roles whenever the workload's architecture allows it.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.