Courseiva

SCS-C02 Identity and Access Management Practice Question

Which TWO are valid ways to authenticate an IAM user?

⚠ Common exam trap

The trap is considering MFA as a primary authentication method. Candidates might select MFA token as a way to authenticate, but it is only a second factor. Another trap is confusing SSH keys with IAM authentication; SSH keys are for EC2 instances, not IAM users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password

Option C (Password) is correct because an IAM user with console access authenticates to the AWS Management Console using a user name and password, which is the standard sign-in credential for interactive console sessions. Option E (Access keys, i.e., access key ID and secret access key) is correct because programmatic requests to AWS APIs, CLI, and SDKs are signed with an access key ID and secret access key pair tied to the IAM user. Option A (SSL/TLS certificate) is not a valid IAM user authentication method; X.509 certificates are used for signing SOAP requests in limited legacy scenarios, not as a general IAM user credential. Option B (MFA token) is not a standalone authentication method — it is a second factor used in addition to a password or access key, not a primary credential by itself. Option D (SSH key pair) is not an IAM authentication mechanism; SSH keys are used for logging into EC2 instances (e.g., via CodeCommit or instance access), not for authenticating to AWS as an IAM user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSL/TLS certificate

    Why it's wrong here

    SSL/TLS certificates are not recognized by the IAM user authentication process. While AWS services such as API Gateway can use client certificates for mutual TLS, IAM itself never validates a certificate as proof of identity for console or API access. Server certificates in IAM are used only to enable HTTPS on your custom domain, which authenticates the server, not the user. Thus, a certificate cannot substitute for an IAM password or access key.

  • ✗

    MFA token

    Why it's wrong here

    An MFA token provides a one-time code that must be combined with a primary credential—either a password for console sign-in or an access key for programmatic requests—to complete authentication. AWS treats MFA as an additional security factor designed to protect against credential theft, not as a standalone authentication method. While IAM policies can require MFA as a condition, the token itself never initiates an authenticated session. Therefore, an MFA token alone cannot authenticate an IAM user.

  • ✓

    Password

    Why this is correct

    An IAM user password is the primary authentication factor for the AWS Management Console, entered together with the account ID or alias at the sign-in page. This password is stored as a login profile for the IAM user and can be rotated manually by the user or administratively by an account administrator. It functions as a persistent credential that grants full access to the console session. This is one of the two standard ways to authenticate an IAM user.

  • ✗

    SSH key pair

    Why it's wrong here

    SSH key pairs are primarily used to authenticate to EC2 instances over SSH, not to the AWS account itself. Although IAM supports uploading SSH public keys for use with AWS CodeCommit over SSH, this is a service-specific repository authentication mechanism, not a general IAM user authentication credential. An SSH key pair does not sign AWS API requests or allow console access. Therefore, it is not a valid way to authenticate an IAM user to AWS.

  • ✓

    Access keys (access key ID and secret access key)

    Why this is correct

    An IAM user access key consists of an access key ID and a secret access key, which together are used with AWS Signature Version 4 to sign programmatic requests to the AWS API and CLI. These keys are long-term credentials tied to the IAM user and can be created, rotated, or deactivated by the user or an administrator. Unlike a password, access keys do not permit console login. They are the standard authentication method for all programmatic AWS access.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.