StudyToCert

All certifications / Developer Associate / Lessons

AWS Certified Developer – Associate DVA-C02 · Domain 2: Security

IAM for applications: execution roles, instance profiles, ECS task roles, least-privilege policies, policy evaluation (explicit deny wins)

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Applications need permissions just as people do, and AWS Identity and Access Management (IAM) provides them through roles. A role is an identity with permission policies but no long-term password or access keys; whoever is allowed to assume it gets temporary credentials from the AWS Security Token Service (STS). Giving your code a role, rather than embedding an IAM user's access keys, is the pattern the exam expects every time.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Developer Associate for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Developer Associate study plan