AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

A company wants to allow an external auditing firm to access specific read-only resources in its AWS account without creating individual IAM users or sharing long-term credentials. Which approach follows AWS best practices?

  1. ACreate individual IAM users with long-term access keys for each auditor
  2. BCreate an IAM role with a trust policy allowing the auditing firm's AWS account to assume it, and attach a read-only permissions policy
  3. CEnable an AWS Config aggregator and grant the firm access to the Config console
  4. DShare the company's root account credentials with the auditing firm temporarily
Show answer & explanation

Correct answer: B. Create an IAM role with a trust policy allowing the auditing firm's AWS account to assume it, and attach a read-only permissions policy

Cross-account IAM roles allow an external AWS account to assume a role with a defined trust policy and scoped permissions, granting temporary, auditable access without sharing long-term credentials — the recommended pattern for third-party access.

Why the other options are wrong

  • A. Long-term access keys for external parties increase risk and violate least privilege.
  • C. Config aggregators consolidate compliance data; they don't grant external account access.
  • D. Sharing root credentials is a severe security anti-pattern.

Cross-Account IAM Role

A cross-account IAM role has a trust policy specifying which external AWS account can assume it, providing temporary, scoped access without sharing long-term credentials.

  • Trust policy defines who can assume the role
  • Permissions policy defines what the role can do
  • Temporary credentials are issued via AWS STS when the role is assumed

Memory trick: Lend the key temporarily, don't give away the house

More Security and Compliance questions