Courseiva

SCS-C02 Identity and Access Management Practice Question

Which TWO actions can be performed using AWS IAM? (Choose two.)

⚠ Common exam trap

Candidates often confuse IAM's authorization capabilities (granting permissions) with the ability to directly perform resource operations, leading them to select options like A, B, or E that are actual AWS actions but are not performed by IAM itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define a password policy for IAM users

AWS IAM allows you to define a password policy for IAM users, which enforces complexity requirements, rotation periods, and reuse prevention. This is a core IAM feature that helps secure user credentials without relying on external identity providers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the instance type of an RDS database

    Why it's wrong here

    Changing an RDS instance type is a database lifecycle operation executed by the Amazon RDS service through the ModifyDBInstance API or the RDS console. IAM never performs such modifications; it only controls whether an identity is authorized to call rds:ModifyDBInstance by evaluating permissions policies. Thus, while IAM can gate the request, the actual instance type change is an RDS action, not an IAM action.

  • ✗

    Create a CloudFront distribution

    Why it's wrong here

    Creating a CloudFront distribution is performed through the Amazon CloudFront service using the CreateDistribution API or the console, which handles edge locations, cache behaviors, and origin configuration. IAM does not contain a native action to create distributions; it only grants or denies the cloudfront:CreateDistribution permission to a user or role. Therefore, provisioning a distribution is a CloudFront operation, not an action performed using AWS IAM.

  • ✓

    Define a password policy for IAM users

    Why this is correct

    Defining an account password policy is a core IAM feature: IAM provides the UpdateAccountPasswordPolicy API and a dedicated console page to enforce policies such as minimum password length, complexity, expiration, and reuse prevention for all IAM users. This policy is stored and enforced by the IAM service as part of its identity-management responsibilities. Since IAM directly manages user credentials, password policy configuration is one of the two actions correctly performed using AWS IAM.

  • ✓

    Create an IAM role with a trust policy for EC2

    Why this is correct

    Creating an IAM role with a trust policy is an IAM-native operation: you use the IAM CreateRole API to define the role and attach a trust policy specifying which principal, such as ec2.amazonaws.com, is allowed to assume it. This role, combined with an instance profile, lets EC2 instances obtain temporary security credentials from AWS STS. Building that role and its trust relationship is entirely an IAM action, making it the second correct answer.

  • ✗

    Configure a VPC peering connection

    Why it's wrong here

    Configuring a VPC peering connection is a networking task owned by Amazon VPC, implemented through the ec2:CreateVpcPeeringConnection API and VPC console, followed by route table updates. IAM is not the service that creates the peering link; at most, an IAM policy can authorize a user to call the VPC API. Since the peering connection and its routing are managed by VPC and not by IAM, this is not an action performed using AWS IAM.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.