Skip to content
BytePatterns

SCS-C03 · Domain 4: Identity and Access Management · 20% of the exam

Task 4.1: Design, implement, and troubleshoot authentication strategies

Proving who is calling: IAM Identity Center and external identity providers for people, Cognito for application users, MFA, temporary credentials from STS and presigned URLs, and tracing a failed sign-in through CloudTrail and the directory.

Study it

  • Workforce identity: IAM Identity Center, permission sets and external IdPs

    Lesson coming

  • Customer identity: Cognito user pools, identity pools and MFA

    Lesson coming

  • Temporary credentials: STS, roles and presigned URLs

    Partly covered by: Shared Responsibility & IAM, Design a System on AWS

  • Troubleshooting sign-in: CloudTrail, Identity Center and Directory Service

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 2

A company manages its workforce in an external SAML 2.0 identity provider and uses AWS IAM Identity Center for access to 60 AWS accounts. Employees must sign in with their corporate credentials, and users and groups must be created, updated and removed in Identity Center automatically when they change in the identity provider. Which steps should the company take? (Choose TWO.)

  1. ACreate an IAM SAML identity provider in each of the 60 member accounts
  2. BDeploy AD Connector in a shared VPC and point it at the identity provider
  3. CCreate an Amazon Cognito user pool that federates with the identity provider
  4. DSet the external IdP as the Identity Center identity source using SAML 2.0
  5. ETurn on SCIM automatic provisioning between the IdP and Identity Center
Show the answer and why
  • ACreate an IAM SAML identity provider in each of the 60 member accounts

    Incorrect

    That is per-account IAM federation, which bypasses Identity Center and provisions nothing.

  • BDeploy AD Connector in a shared VPC and point it at the identity provider

    Incorrect

    AD Connector is a gateway to an on-premises Microsoft Active Directory, not to a SAML identity provider.

  • CCreate an Amazon Cognito user pool that federates with the identity provider

    Incorrect

    Cognito user pools serve application users, not workforce access to AWS accounts through Identity Center.

  • DSet the external IdP as the Identity Center identity source using SAML 2.0

    Correct

    Connecting the external IdP through SAML 2.0 lets users sign in to the AWS access portal with their corporate credentials.

  • ETurn on SCIM automatic provisioning between the IdP and Identity Center

    Correct

    SAML cannot query the IdP for users and groups; SCIM provisioning keeps them synchronized in Identity Center.

With an external IdP, SAML handles sign-in and SCIM handles who exists. Users and groups must be provisioned before they can be assigned to accounts.

Question 2 · choose 1

A consumer app uses an Amazon Cognito user pool. The security team wants users to be asked for an additional factor only when a sign-in looks risky, for example from a new device or location, and wants sign-ins with passwords known from public breaches to be blocked. The team wants to avoid custom code. What should the team do?

  1. ASet MFA to required for all users with authenticator apps and SMS allowed
  2. BAssociate an AWS WAF web ACL that has a rate-based rule with the user pool
  3. CRaise the minimum password length and require symbols in the password policy
  4. DTurn on Cognito threat protection in full function mode
Show the answer and why
  • ASet MFA to required for all users with authenticator apps and SMS allowed

    Incorrect

    Required MFA makes every user complete MFA at every sign-in, not only risky ones, and does nothing about leaked passwords.

  • BAssociate an AWS WAF web ACL that has a rate-based rule with the user pool

    Incorrect

    A web ACL filters requests by IP, headers and similar data. It cannot see passwords and does not score sign-in risk.

  • CRaise the minimum password length and require symbols in the password policy

    Incorrect

    A longer password policy does not detect passwords that have already leaked, nor adapt MFA to risk.

  • DTurn on Cognito threat protection in full function mode

    Correct

    Threat protection scores sign-in risk and can require MFA or block, and checks credentials against leaked lists. It is part of the Plus plan.

Risk-based MFA and leaked-password checks are the two parts of Cognito threat protection, formerly called advanced security features.

Question 3 · choose 1

A backend assumes an IAM role with AssumeRole and default settings, then generates S3 presigned URLs with a 24-hour expiration for partners to download reports. Partners report that links stop working after about an hour. Security does not allow long-term IAM credentials. Which change lets links stay valid for 24 hours?

  1. ARequest an expiration of 86,400 seconds explicitly when generating each presigned URL
  2. BHave the backend assume a second role from the first role to get fresh credentials for signing
  3. CDeliver the files through CloudFront with signed URLs that expire after 24 hours
  4. DRaise the role's maximum session duration to 12 hours and request the longest sessions
Show the answer and why
  • ARequest an expiration of 86,400 seconds explicitly when generating each presigned URL

    Incorrect

    A presigned URL made with temporary credentials expires when those credentials expire, whatever expiration is requested.

  • BHave the backend assume a second role from the first role to get fresh credentials for signing

    Incorrect

    Role chaining limits the session to one hour, so the URLs would still stop working after an hour.

  • CDeliver the files through CloudFront with signed URLs that expire after 24 hours

    Correct

    A CloudFront signed URL carries its own expiration date and time, signed with a key from a trusted key group, so it does not depend on an IAM session.

  • DRaise the role's maximum session duration to 12 hours and request the longest sessions

    Incorrect

    The maximum role session is 12 hours, so URLs signed with those credentials still expire before 24 hours.

An S3 presigned URL lives no longer than the credentials that signed it. Without long-term keys, a 24-hour link needs a signing mechanism that is not tied to an IAM session.

Question 4 · choose 1

A team created a CloudWatch Logs metric filter and alarm for failed AWS Management Console sign-ins by IAM users. The filter reads a single-Region trail in eu-west-1 that sends events to CloudWatch Logs. Users sign in through the global sign-in endpoint, and failed sign-ins have happened, but the alarm never fires. What should the team change?

  1. AMake the trail a multi-Region trail
  2. BAdd a data event selector for the sign-in service to the trail
  3. CTurn on CloudTrail Insights events for the trail
  4. DRequire MFA for the IAM users so that failed attempts are logged
Show the answer and why
  • AMake the trail a multi-Region trail

    Correct

    With the global endpoint, CloudTrail records ConsoleLogin events in Regions such as us-east-1, not in eu-west-1, so a single-Region trail there misses them.

  • BAdd a data event selector for the sign-in service to the trail

    Incorrect

    ConsoleLogin events are management events, which the trail already logs where they are recorded.

  • CTurn on CloudTrail Insights events for the trail

    Incorrect

    Insights flags unusual API call or error rates. It does not change in which Region sign-in events are recorded.

  • DRequire MFA for the IAM users so that failed attempts are logged

    Incorrect

    CloudTrail already records unsuccessful sign-ins without MFA. MFA does not change where the events are recorded.

Console sign-in events land in a Region decided by the user type and the sign-in endpoint. Alerts on them need a trail that covers those Regions, which a multi-Region trail does.

Question 5 · choose 1

A company provisions users and groups into IAM Identity Center from an external identity provider with SCIM. An administrator deleted the Finance group in the identity provider by mistake and re-created it with the same name and members. The Identity Center console still shows Finance assigned to the finance account with its permission set, but members can no longer access the account. What should the administrator do?

  1. ARe-provision the permission set to the finance account from Identity Center
  2. BRotate the SCIM access token in both Identity Center and the identity provider
  3. CRemove the old group's account assignment and assign the group again
  4. DIncrease the session duration of the permission set to 12 hours
Show the answer and why
  • ARe-provision the permission set to the finance account from Identity Center

    Incorrect

    Provisioning pushes the permission set's policies to the account; the assignment still points to the deleted group.

  • BRotate the SCIM access token in both Identity Center and the identity provider

    Incorrect

    Synchronization works, as the re-created group shows. A new token does not change which group ID the assignment references.

  • CRemove the old group's account assignment and assign the group again

    Correct

    The re-created group has a new internal identifier. The assignment still references the deleted group's ID, so it must be removed and made again.

  • DIncrease the session duration of the permission set to 12 hours

    Incorrect

    Session duration controls how long access lasts after sign-in, not whether the group has access at all.

Identity Center assigns by internal ID, not by name. A group deleted and re-created in the IdP is a new group, even when the name shows unchanged in the console.

Question 6 · choose 1

A mobile app signs users in with an Amazon Cognito user pool and gets AWS credentials from a Cognito identity pool. All signed-in users receive the same IAM role. Each user may read and write only objects under their own prefix in an S3 bucket. How should the role's policy express the prefix?

  1. AUse the ${aws:username} policy variable in the resource ARN
  2. BUse ${cognito-identity.amazonaws.com:sub} in the resource ARN
  3. CUse the sub claim of the user pool ID token as the prefix in object keys
  4. DCreate one IAM role per user and map each user to it with role rules
Show the answer and why
  • AUse the ${aws:username} policy variable in the resource ARN

    Incorrect

    aws:username is not present for web identity federated sessions, so the policy would not resolve to a per-user prefix.

  • BUse ${cognito-identity.amazonaws.com:sub} in the resource ARN

    Correct

    This variable resolves to the user's identity ID in the identity pool, so one policy limits every user to a prefix of their own.

  • CUse the sub claim of the user pool ID token as the prefix in object keys

    Incorrect

    The identity pool's sub is the identity ID, not the user pool sub, so the prefix in the keys would not match what the policy evaluates.

  • DCreate one IAM role per user and map each user to it with role rules

    Incorrect

    Per-user roles do not scale and are not needed when a policy variable can express the per-user prefix.

A policy variable turns one policy into per-user permissions. For identity pools, the variable is the identity ID, not a user pool attribute.

Question 7 · choose 1

An application on EC2 reads objects from S3 using access keys stored in a configuration file on the instance. What is the recommended way to give it credentials instead?

  1. AStore the access keys in an environment variable
  2. BUse an IAM role through an instance profile
  3. CCreate a new IAM user for each instance
  4. DRotate the access keys every week with a script
Show the answer and why
  • AStore the access keys in an environment variable

    Incorrect

    The keys are still long-term credentials on the instance.

  • BUse an IAM role through an instance profile

    Correct

    A role supplies temporary credentials to applications on the instance, so no long-term keys have to be distributed or rotated.

  • CCreate a new IAM user for each instance

    Incorrect

    More IAM users mean more long-term keys to manage.

  • DRotate the access keys every week with a script

    Incorrect

    Rotation helps, but the application still holds long-term keys.

The SDKs pick up instance profile credentials automatically, so no code change is usually needed.

Question 8 · choose 1

An account still has a few IAM users with console passwords. Security wants a minimum password length and complexity for them. What should the team configure, and what does it cover?

  1. AAn account password policy, which also covers the root user
  2. BAn account password policy, which applies to IAM users
  3. CAn SCP that requires long passwords for IAM users
  4. DAn account password policy, which also covers access keys
Show the answer and why
  • AAn account password policy, which also covers the root user

    Incorrect

    The IAM password policy does not apply to the root user's password.

  • BAn account password policy, which applies to IAM users

    Correct

    A custom password policy sets complexity and rotation rules for IAM users' passwords.

  • CAn SCP that requires long passwords for IAM users

    Incorrect

    SCPs control API permissions, not password rules.

  • DAn account password policy, which also covers access keys

    Incorrect

    The password policy does not apply to IAM users' access keys.

Better still, move people to federation and remove IAM user passwords where possible.

Question 9 · choose 1

A script that runs once a month uses access keys of the AWS account root user. What does AWS recommend?

  1. AKeep the keys and rotate them every 90 days
  2. BKeep the keys but store them in Secrets Manager
  3. CDelete the root keys and use an IAM role
  4. DTurn on MFA for the root user and keep the keys
Show the answer and why
  • AKeep the keys and rotate them every 90 days

    Incorrect

    AWS recommends not having root user access keys at all.

  • BKeep the keys but store them in Secrets Manager

    Incorrect

    Storing them better does not remove the risk of root access keys.

  • CDelete the root keys and use an IAM role

    Correct

    AWS strongly recommends not creating root user access keys; the script should use a role with only the permissions it needs.

  • DTurn on MFA for the root user and keep the keys

    Incorrect

    MFA protects sign-in; root access keys still give full access.

Root credentials are for the few tasks that require the root user, not for automation.

Question 10 · choose 1

A mobile app needs users to sign up and sign in, and signed-in users must upload photos directly to S3 with temporary AWS credentials. Which Amazon Cognito components are needed?

  1. AA user pool for sign-in and an identity pool for credentials
  2. BOnly a user pool, whose ID token is accepted by S3 directly
  3. COnly an identity pool with unauthenticated access for everyone
  4. DAn IAM user for every app user, created at sign-up
Show the answer and why
  • AA user pool for sign-in and an identity pool for credentials

    Correct

    User pools authenticate users and issue tokens; identity pools exchange those tokens for temporary AWS credentials.

  • BOnly a user pool, whose ID token is accepted by S3 directly

    Incorrect

    S3 does not accept user pool tokens; it needs AWS credentials.

  • COnly an identity pool with unauthenticated access for everyone

    Incorrect

    That skips sign-in, which the app requires.

  • DAn IAM user for every app user, created at sign-up

    Incorrect

    IAM users are not meant for app end users and do not scale for them.

Authentication answers who the user is; authorization answers which AWS resources the user may reach.

Question 11 · choose 1

A company has 200 employees with IAM users in 15 accounts. It wants people to sign in once with their corporate identities and get temporary credentials in each account. What should it adopt?

  1. AOne shared IAM user per team in each account
  2. BIAM users with MFA in a single account only
  3. CAccess keys stored in a central password manager
  4. DIAM Identity Center with the corporate IdP
Show the answer and why
  • AOne shared IAM user per team in each account

    Incorrect

    Shared users remove accountability and keep long-term credentials.

  • BIAM users with MFA in a single account only

    Incorrect

    IAM users still have long-term passwords and keys.

  • CAccess keys stored in a central password manager

    Incorrect

    Access keys are long-term credentials, not federation.

  • DIAM Identity Center with the corporate IdP

    Correct

    Human users should use federation with an identity provider and temporary credentials, which IAM Identity Center provides.

Permission sets then define what each group can do in each account.

Practise domain 4 →Practise all domains →