SCS-C02 Identity and Access Management Practice Question
Which THREE are valid methods for authenticating to AWS APIs? (Choose THREE.)
⚠ Common exam trap
SCS-C02 often tests the confusion between authentication methods for AWS APIs versus other AWS services (e.g., SSH for EC2, client certificates for API Gateway), so candidates must remember that AWS APIs specifically use IAM credentials, federation, and temporary credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access key ID and secret access key
Option A (access key ID and secret access key) is correct because long-term IAM user credentials are signed into requests via SigV4 to authenticate to AWS APIs such as the CLI, SDKs, and REST endpoints. Option C (SAML federation) is correct because AWS supports SAML 2.0-based identity federation through IAM roles and STS (AssumeRoleWithSAML), letting corporate directory users obtain temporary AWS credentials for API access. Option E (IAM role temporary credentials) is correct because STS issues short-lived credentials (access key, secret key, and session token) via AssumeRole or instance profiles, which are a standard way to authenticate API calls. Option B (SSH key pair) is not valid for AWS API authentication, as SSH keys are used for EC2 instance login, not for signing AWS API requests. Option D (client certificate) is not a general AWS API authentication method; mutual TLS client certificates are used for specific services like IoT or API Gateway custom authorizers, not as a standard AWS API credential type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Access key ID and secret access key
Why this is correct
Long-term IAM user credentials, an access key ID and secret access key, are the canonical way to sign AWS API requests via Signature Version 4. These credentials are used for programmatic access through the AWS CLI, SDKs, or direct HTTP calls, and must be protected with least-privilege IAM policies and rotated regularly because they do not expire by default.
- ✗
SSH key pair
Why it's wrong here
An SSH key pair authenticates an entity to an EC2 instance for interactive shell access or secure file transfer, not to the AWS control plane or data-plane APIs. AWS APIs are signed with IAM-based credentials or federation mechanisms, so while SSH keys are valid for instance-level OS authentication, they are never accepted as AWS API authentication material.
- ✓
SAML federation
Why this is correct
SAML federation is a valid authentication method because it enables an external identity provider (IdP) to assert a user's identity to AWS via the AWS SSO or STS AssumeRoleWithSAML API. The IdP issues a SAML assertion that contains attributes mapped to IAM roles and session duration, allowing the user to receive temporary credentials and call AWS APIs without a long-lived IAM access key.
- ✗
Client certificate
Why it's wrong here
Client certificates are not a supported authentication mechanism for the standard AWS REST/query APIs. While mutual TLS is available for some AWS services like API Gateway or certain service-specific endpoints for compliance, it is not a general-purpose method for authenticating API calls; AWS API access relies on cryptographic request signing with AWS credentials or temporary credentials from federation, not X.509 client certificates for API authentication.
- ✓
IAM role temporary credentials
Why this is correct
IAM role temporary credentials are a valid method because they are obtained dynamically from AWS STS via AssumeRole, GetFederationToken, or, in ECS, the task role credential endpoint. These credentials consist of an access key ID, a secret access key, and a session token, and they are time-limited (default up to 12 hours for AssumeRole), making them ideal for cross-account access or workloads running on EC2 instances with instance profiles.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.