nerdexam
Amazon

SCS-C02 · Question #375

You are planning to use AWS Configto check the configuration of the resources in your AWS account. You are planning on using an existing IAM role and using it for the AWS Config resource. Which of…

The correct answer is A. Ensure that there is a trust policy in place for the AWS Config service within the role. Options B,C and D are invalid because you need to ensure a trust policy is in place and not a https://docs.aws.amazon.com/config/latest/developerguide/iamrole-permissions.html

Submitted by stefanr· Mar 6, 2026Identity and Access Management

Question

You are planning to use AWS Configto check the configuration of the resources in your AWS account. You are planning on using an existing IAM role and using it for the AWS Config resource. Which of the following is required to ensure the AWS config service can work as required?

Exhibit

SCS-C02 question #375 exhibit

Options

  • AEnsure that there is a trust policy in place for the AWS Config service within the role
  • BEnsure that there is a grant policy in place for the AWS Config service within the role
  • CEnsure that there is a user policy in place for the AWS Config service within the role
  • DEnsure that there is a group policy in place for the AWS Config service within the role

How the community answered

(50 responses)
  • A
    70% (35)
  • B
    4% (2)
  • C
    18% (9)
  • D
    8% (4)

Explanation

Options B,C and D are invalid because you need to ensure a trust policy is in place and not a https://docs.aws.amazon.com/config/latest/developerguide/iamrole-permissions.html

Topics

#AWS Config#IAM role trust policy#service role#cross-service permissions

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice