AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
A company wants to allow an external auditing firm to access specific read-only resources in its AWS account without creating individual IAM users or sharing long-term credentials. Which approach follows AWS best practices?
- ACreate individual IAM users with long-term access keys for each auditor
- BCreate an IAM role with a trust policy allowing the auditing firm's AWS account to assume it, and attach a read-only permissions policy
- CEnable an AWS Config aggregator and grant the firm access to the Config console
- DShare the company's root account credentials with the auditing firm temporarily
Show answer & explanationAnswer & explanation
Correct answer: B. Create an IAM role with a trust policy allowing the auditing firm's AWS account to assume it, and attach a read-only permissions policy
Cross-account IAM roles allow an external AWS account to assume a role with a defined trust policy and scoped permissions, granting temporary, auditable access without sharing long-term credentials — the recommended pattern for third-party access.
Why the other options are wrong
- A. Long-term access keys for external parties increase risk and violate least privilege.
- C. Config aggregators consolidate compliance data; they don't grant external account access.
- D. Sharing root credentials is a severe security anti-pattern.
Cross-Account IAM Role
A cross-account IAM role has a trust policy specifying which external AWS account can assume it, providing temporary, scoped access without sharing long-term credentials.
- Trust policy defines who can assume the role
- Permissions policy defines what the role can do
- Temporary credentials are issued via AWS STS when the role is assumed
Memory trick: Lend the key temporarily, don't give away the house