Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 36 pages
Exam (elaborations)

AWS CLF-C02 IAM Security Practice Test 2026–2027 | Users, Groups, Roles, Policies & Access Control Questions with Answers

Document preview thumbnail
Preview 4 out of 36 pages

Master AWS Identity and Access Management (IAM) for the AWS Cloud Practitioner CLF-C02 2026–2027 certification with targeted security-focused practice. Review the functions of IAM users, groups, roles, and policies, along with permissions, authentication, authorization, least-privilege access, and temporary credentials. Realistic questions test your ability to identify the correct identity or access-control mechanism for different AWS scenarios. Detailed answers and rationales explain policy behavior and reinforce practical IAM concepts. Designed for students, IT professionals, cloud practitioners, and certification candidates seeking comprehensive IAM and AWS security preparation.

Content preview

___________________________________________________________________


AWS Cloud Practitioner IAM Users,
Groups, Roles & Policies Practice Test
2026–2027 | AWS Identity Questions,
Answers & Detailed Rationales

1. What is the primary purpose of AWS Identity and Access Management
(IAM)?

A. To monitor application performance
B. To control access to AWS resources
C. To encrypt data stored in Amazon S3
D. To provide DNS resolution

Answer: B. To control access to AWS resources

Rationale: IAM enables you to securely control authentication and authorization
for AWS resources by defining who can access what and under which conditions.

2. Which IAM identity is intended to represent a person or application that
needs long-term AWS credentials?

A. IAM role
B. IAM policy
C. IAM user
D. IAM group

,Answer: C. IAM user

Rationale: An IAM user represents an individual person or workload requiring
persistent credentials. Roles are generally preferred for temporary access.

3. What is an IAM group primarily used for?

A. Storing AWS access keys
B. Assigning permissions to multiple IAM users
C. Creating temporary credentials
D. Encrypting IAM policies

Answer: B. Assigning permissions to multiple IAM users

Rationale: IAM groups allow administrators to attach permissions policies to a
collection of users, simplifying permission management.

4. Which IAM identity is designed to provide temporary permissions that can
be assumed by trusted entities?

A. IAM user
B. IAM group
C. IAM role
D. IAM root account

Answer: C. IAM role

Rationale: IAM roles provide temporary security credentials and can be assumed
by users, applications, AWS services, or federated identities.

5. Which statement about IAM roles is correct?

A. Roles always require permanent access keys
B. Roles are only available to the root user
C. Roles provide temporary security credentials when assumed
D. Roles can contain other IAM roles

Answer: C. Roles provide temporary security credentials when assumed

,Rationale: AWS Security Token Service (STS) issues temporary credentials when
an IAM role is assumed.

6. What does an IAM policy primarily define?

A. Network routes
B. Resource pricing
C. Permissions and access conditions
D. Encryption algorithms only

Answer: C. Permissions and access conditions

Rationale: IAM policies define allowed or denied actions on resources and can
include conditions controlling when access is permitted.

7. Which format are identity-based IAM policies commonly written in?

A. YAML only
B. XML only
C. JSON
D. CSV

Answer: C. JSON

Rationale: IAM policies use JSON syntax to specify elements such as Effect,
Action, Resource, and Condition.

8. Which IAM policy element specifies whether a statement allows or denies
access?

A. Action
B. Effect
C. Principal
D. Resource

Answer: B. Effect

, Rationale: The Effect element specifies either Allow or Deny for the permissions
described by the statement.

9. Which IAM policy element specifies the AWS API operations affected by the
policy?

A. Action
B. Resource
C. Principal
D. Version

Answer: A. Action

Rationale: The Action element identifies the API operations, such as
s3:GetObject or ec2:StartInstances, to which the statement applies.

10.Which IAM policy element identifies the AWS resource to which a
permission applies?

A. Principal
B. Resource
C. Effect
D. Condition

Answer: B. Resource

Rationale: Resource specifies the ARN or resource scope affected by the policy
statement.

11.Which IAM policy element can restrict access based on attributes such as
source IP address or MFA status?

A. Condition
B. Version
C. Sid
D. Principal

Answer: A. Condition

Document information

Uploaded on
September 1, 2026
Number of pages
36
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
mml1030
2.6
(5)
Sold
8
Followers
0
Items
1207
Last sold
5 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions