Courseiva
mediumMultiple Choice

SSCP Uses AWS IAM to manage access Practice Question

An organization uses AWS IAM to manage access. Which best practice ensures least privilege?

⚠ Common exam trap

SSCP often tests the misconception that administrative convenience (shared admin account, root usage) is acceptable — candidates must recognize that least privilege requires unique identities and minimal scoped permissions, not just 'admin for everyone.'

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create individual users and assign only necessary permissions

Least privilege means granting each identity only the permissions required to perform its job. Creating individual IAM users (or roles) and attaching narrowly scoped policies that grant only necessary actions on specific resources enforces this principle and provides accountability through unique credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a single shared admin account

    Why it's wrong here

    A shared admin account grants every user full privileges, eliminating individual accountability and any least-privilege boundary. It is tempting because it simplifies administration; least privilege requires unique identities with scoped IAM policies and roles, granting only the permissions each task needs.

  • ✗

    Use root account for administrative tasks

    Why it's wrong here

    The root account holds unrestricted access that cannot be scoped by IAM policies, so using it for routine administration violates least privilege. It is tempting because root always works; it should be locked away with MFA, while daily tasks use scoped IAM users or roles.

  • ✓

    Create individual users and assign only necessary permissions

    Why this is correct

    Granting each identity only the permissions its role requires enforces least privilege at the IAM policy level, rather than sharing credentials or attaching broad managed policies. Individual accounts also preserve accountability through distinct audit trails.

  • ✗

    Grant all users full access to S3 buckets

    Why it's wrong here

    Granting full S3 access to every user violates least privilege outright, since permissions must be scoped to each identity's required actions and resources. It is tempting because broad grants avoid access-denied troubleshooting, and would suit a sandbox account where no sensitive data or separation of duties exists.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.