SCS-C02 Identity and Access Management Practice Question
Which TWO statements are true about IAM roles? (Choose two.)
⚠ Common exam trap
SCS-C02 often tests the characteristics of IAM roles, and candidates might mistakenly think roles are regional or provide permanent credentials; the key is that roles are global and provide temporary credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM roles can be used by federated users.
Option A is correct because IAM roles support identity federation: users authenticated by an external identity provider (via SAML 2.0 or OIDC, or via AWS STS AssumeRoleWithSAML/AssumeRoleWithWebIdentity) receive temporary credentials scoped to the role's permissions rather than needing IAM user accounts. Option E is correct because AWS services can assume roles through a trust policy that names the service principal (for example, ec2.amazonaws.com), which is exactly how an instance profile lets EC2 instances obtain temporary credentials from the instance metadata service. Option B is wrong because IAM roles, like IAM users and policies, are global resources not tied to a specific AWS region. Option C is wrong because roles are in fact attached to EC2 instances via instance profiles. Option D is wrong because roles never issue permanent access keys; they provide temporary credentials through AWS STS with automatic rotation and expiration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IAM roles can be used by federated users.
Why this is correct
Federated users, such as those authenticated by an external identity provider via SAML 2.0 or web identity federation, can assume an IAM role to obtain temporary AWS credentials. The user's original identity is mapped to a role, and AWS STS issues scoped, time-limited access keys that abide by the role's trust and permissions policies. This allows external identities to access AWS resources without creating an IAM user and without distributing permanent credentials.
- ✗
IAM roles are specific to an AWS region.
Why it's wrong here
IAM roles are global entities defined within an AWS account, not scoped to a specific region. Role definitions, including their policies and trust relationships, are stored in the IAM global service partition and appear across all regions in the management console. While the STS endpoint that issues temporary credentials is regional (e.g., sts.us-east-1.amazonaws.com), the role itself is not. Therefore, a role created in one region is usable in every region, unless a condition in its policy explicitly restricts usage geographically.
- ✗
IAM roles cannot be attached to an EC2 instance.
Why it's wrong here
An IAM role can absolutely be attached to an EC2 instance using an instance profile, which is a container for the role. When an instance is launched with a role, the AWS credentials are made available through the instance metadata service (IMDS), and the instance automatically assumes the role to receive temporary credentials. This removes the need to manually place access keys on the instance, which is a security best practice. The role must have a trust policy allowing ec2.amazonaws.com as a principal.
- ✗
IAM roles have permanent access keys.
Why it's wrong here
IAM roles do not have permanent access keys at all; they are identities, not credentials. Instead, when an entity assumes a role, AWS STS dynamically generates temporary security credentials consisting of an access key, secret access key, and session token, which expire after a configurable session duration (default one hour, up to 12 hours for role sessions). These temporary credentials include a session token that must be passed with every API call, making them inherently less risky than long-lived access keys because they are automatically rotated upon expiration.
- ✓
IAM roles can be assumed by AWS services like EC2.
Why this is correct
AWS services such as EC2 are common principals for IAM roles. An EC2 instance can be launched with a role attached through an instance profile, causing the instance to assume the role automatically and receive temporary credentials from the instance metadata service. Applications running on the instance then make authenticated API calls using these credentials, eliminating the need to embed static keys. This pattern currently supports any service that can be configured with a service role, such as Lambda, ECS, and RDS.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.