StudyToCert

All certifications / Security Specialty / Lessons

AWS Certified Security – Specialty SCS-C03 · Domain 4: Identity and Access Management

Temporary credentials: IAM roles, STS AssumeRole, trust policies, external IDs and the confused deputy problem

▶ Watch the overview video

Last reviewed September 29, 2026 · Leer en español

IAM roles are the preferred way to grant access on AWS because they use temporary credentials that expire automatically. The AWS Security Token Service (STS) issues these credentials when a trusted principal assumes the role.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 3 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security Specialty for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security Specialty study plan