SCS-C02 Identity and Access Management Practice Question
Which TWO are valid IAM identity-based policies? (Choose 2.)
⚠ Common exam trap
SCS-C02 often tests the confusion between identity-based and resource-based policies, so candidates incorrectly select trust policies or S3 bucket policies as identity-based because they all use similar JSON syntax.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inline policy
An inline policy (B) is a valid IAM identity-based policy because it is an embedded JSON policy document attached directly to a single IAM user, group, or role, granting or denying that identity's permissions. An AWS managed policy (E) is also a valid identity-based policy since it is a standalone, AWS-authored policy that can be attached to IAM users, groups, or roles as their permissions policy. By contrast, a trust policy (A) is a resource-based policy on an IAM role that defines which principals may assume it via sts:AssumeRole, not an identity-based permissions policy. An S3 bucket policy (C) is a resource-based policy attached to the bucket, and a service control policy (D) is an AWS Organizations guardrail that sets maximum permissions for accounts, not an identity-based policy attached to an IAM identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trust policy
Why it's wrong here
Trust policies are resource-based policies that are attached to an IAM role. They define the trusted principals (such as AWS accounts, services, or federated users) that are allowed to assume that role, essentially establishing the trust relationship. This is fundamentally different from identity-based policies, which are attached to IAM users, groups, or roles to define what actions those identities can perform. Because a trust policy is attached to a role as a resource and controls who can assume it, it is not a valid identity-based policy type.
- ✓
Inline policy
Why this is correct
Inline policies are identity-based policies that are embedded directly into a single IAM user, group, or role. They are maintained as part of the entity itself, rather than as standalone managed policies, which ensures a strict one-to-one relationship between the policy and the identity. This direct attachment qualifies inline policies as a valid type of identity-based policy in IAM. They are particularly useful when you need to guarantee that a specific policy cannot be accidentally attached to another entity.
- ✗
S3 bucket policy
Why it's wrong here
S3 bucket policies are resource-based policies that are attached to Amazon S3 buckets, not to IAM identities. They specify which principals (users, roles, accounts, or even anonymous callers) are allowed to perform certain actions on the bucket and its objects. Since identity-based policies must be attached to IAM users, groups, or roles, a bucket policy falls outside that category. Therefore, it is not a valid identity-based policy type, even though it can be used to grant permissions.
- ✗
Service control policy (SCP)
Why it's wrong here
Service control policies (SCPs) are organization-level policies used with AWS Organizations to centrally manage the maximum available permissions for all accounts within an organization. They act as permission boundaries that restrict what IAM identity-based policies can grant, but they never grant permissions themselves. SCPs are attached to organizational units, accounts, or the organization root, not to IAM users, groups, or roles. As a result, they are not considered identity-based policies in IAM.
- ✓
AWS managed policy
Why this is correct
AWS managed policies are standalone identity-based policies that are created and managed by AWS. They provide predefined permissions for common use cases and can be attached to multiple IAM users, groups, or roles without needing to copy the policy content. Because they are designed to be attached to IAM identities and define what those identities can do, they are a valid identity-based policy type. AWS managed policies are a core part of IAM's policy management model.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.