Courseiva

SCS-C02 Identity and Access Management Practice Question

Which TWO are IAM best practices? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse IAM roles with IAM users, mistakenly thinking roles are only for cross-account access, when in fact roles are the recommended mechanism for granting permissions to AWS services like EC2, Lambda, and ECS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use conditions in IAM policies to restrict access based on tags or IP addresses.

Using conditions in IAM policies (e.g., `aws:SourceIp`, `aws:RequestTag`) allows you to enforce fine-grained access control based on contextual attributes like IP addresses or resource tags. This follows the principle of least privilege by restricting permissions to only the necessary scope, reducing the attack surface. For example, you can deny access to S3 buckets unless the request originates from a corporate IP range.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Avoid using IAM roles and instead attach policies directly to users.

    Why it's wrong here

    Attaching policies directly to IAM users creates long-lived static credentials, such as an access key ID and secret, that typically end up embedded in code or configuration files. If those keys are leaked, the attached permissions are exposed until an admin detects and rotates them. IAM roles avoid this by leveraging AWS STS to issue temporary credentials, allowing the application to assume a role via an instance profile or a trust policy without storing permanent keys, and roles can also be scoped with permissions boundaries for cross-account access.

  • ✗

    Use the root user for everyday administrative tasks.

    Why it's wrong here

    The AWS root user has unrestricted access to every resource and account setting, and no IAM policy can reduce those permissions, so using it for routine admin work completely defeats least privilege and separation of duties. Everyday actions like launching EC2 instances or managing IAM should be done through an IAM user or role with only the required policies and MFA enforced. The root user should be used only for account-level operations that no other identity can perform, such as closing the account, changing the AWS Support plan, or updating account contact details, and should always be protected with a strong password plus MFA.

  • ✗

    Grant broad permissions to all users to simplify management.

    Why it's wrong here

    Granting broad permissions, for example using 'Action:*' on 'Resource:*', directly violates the least-privilege principle because any compromised credential or misused identity inherits access to every action on every resource. It also inflates the blast radius of a security incident and makes audits difficult to pass because policies no longer reflect the actual operational needs of the workload. The correct practice is to start with AWS managed policies, then use IAM Access Analyzer and CloudTrail logs to develop custom policies that grant only the actions the principal genuinely performs.

  • ✓

    Use conditions in IAM policies to restrict access based on tags or IP addresses.

    Why this is correct

    IAM policy conditions allow you to add context-aware requirements to an allow statement, such as restricting the source IP with 'aws:SourceIp', requiring an MFA token with 'aws:MultiFactorAuthPresent', or limiting EC2 actions based on resource tags with 'ec2:ResourceTag'. This goes beyond identity alone by enforcing that the request also looks like it comes from a trusted network or satisfies other organizational controls. Conditions are a core defense against stolen credentials and are essential for implementing least privilege in real-world environments where access should depend on more than just who is calling.

  • ✓

    Use IAM roles for applications that run on EC2 instances.

    Why this is correct

    Using an IAM role for an EC2 application is a best practice because the instance automatically obtains temporary, rotated credentials through the instance metadata service, eliminating the need to embed access keys in the AMI, user-data, or source code. The role is attached to the instance profile, EC2 assumes the role, and the SDK retrieves credentials that soon expire and are automatically refreshed. This limits the exposure of any single credential and also simplifies key management, since the role's permissions can be adjusted later without redeploying or reconfiguring the instances.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.