Courseiva

SCS-C02 Identity and Access Management Practice Question

Which TWO are valid IAM identity-based policies? (Choose 2.)

⚠ Common exam trap

SCS-C02 often tests the confusion between identity-based and resource-based policies, so candidates incorrectly select trust policies or S3 bucket policies as identity-based because they all use similar JSON syntax.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inline policy

An inline policy (B) is a valid IAM identity-based policy because it is an embedded JSON policy document attached directly to a single IAM user, group, or role, granting or denying that identity's permissions. An AWS managed policy (E) is also a valid identity-based policy since it is a standalone, AWS-authored policy that can be attached to IAM users, groups, or roles as their permissions policy. By contrast, a trust policy (A) is a resource-based policy on an IAM role that defines which principals may assume it via sts:AssumeRole, not an identity-based permissions policy. An S3 bucket policy (C) is a resource-based policy attached to the bucket, and a service control policy (D) is an AWS Organizations guardrail that sets maximum permissions for accounts, not an identity-based policy attached to an IAM identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trust policy

    Why it's wrong here

    Trust policies are resource-based policies that are attached to an IAM role. They define the trusted principals (such as AWS accounts, services, or federated users) that are allowed to assume that role, essentially establishing the trust relationship. This is fundamentally different from identity-based policies, which are attached to IAM users, groups, or roles to define what actions those identities can perform. Because a trust policy is attached to a role as a resource and controls who can assume it, it is not a valid identity-based policy type.

  • ✓

    Inline policy

    Why this is correct

    Inline policies are identity-based policies that are embedded directly into a single IAM user, group, or role. They are maintained as part of the entity itself, rather than as standalone managed policies, which ensures a strict one-to-one relationship between the policy and the identity. This direct attachment qualifies inline policies as a valid type of identity-based policy in IAM. They are particularly useful when you need to guarantee that a specific policy cannot be accidentally attached to another entity.

  • ✗

    S3 bucket policy

    Why it's wrong here

    S3 bucket policies are resource-based policies that are attached to Amazon S3 buckets, not to IAM identities. They specify which principals (users, roles, accounts, or even anonymous callers) are allowed to perform certain actions on the bucket and its objects. Since identity-based policies must be attached to IAM users, groups, or roles, a bucket policy falls outside that category. Therefore, it is not a valid identity-based policy type, even though it can be used to grant permissions.

  • ✗

    Service control policy (SCP)

    Why it's wrong here

    Service control policies (SCPs) are organization-level policies used with AWS Organizations to centrally manage the maximum available permissions for all accounts within an organization. They act as permission boundaries that restrict what IAM identity-based policies can grant, but they never grant permissions themselves. SCPs are attached to organizational units, accounts, or the organization root, not to IAM users, groups, or roles. As a result, they are not considered identity-based policies in IAM.

  • ✓

    AWS managed policy

    Why this is correct

    AWS managed policies are standalone identity-based policies that are created and managed by AWS. They provide predefined permissions for common use cases and can be attached to multiple IAM users, groups, or roles without needing to copy the policy content. Because they are designed to be attached to IAM identities and define what those identities can do, they are a valid identity-based policy type. AWS managed policies are a core part of IAM's policy management model.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.