People blur these together, but they’re different things. Keep them straight and IAM questions get much easier.
Role vs policy
A policy is a JSON document listing permissions — what actions are allowed or denied on what resources. A role is an identity that can be assumed temporarily, and it has policies attached. Users, services (like EC2 and Lambda), and other accounts assume roles to get temporary credentials. Policies define permissions; roles are how you hand those permissions out without long-term keys.
Test yourself
A Lambda function needs permission to write to DynamoDB. What’s the correct way to grant it?
- Attach an execution role (with a DynamoDB policy) to the function
- Hard-code IAM user keys in the function
- Make the DynamoDB table public
- Add the function to a security group
👉 Click to reveal the answer & explanation
Correct answer: A. Lambda assumes an execution role whose attached policy grants DynamoDB access — temporary, rotated credentials, no secrets. Hard-coded keys (B) leak; a public table (C) is insecure; security groups (D) control network traffic, not permissions.
Related topics
AWS IAM · AWS Lambda · AWS Organizations
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first