STS issues temporary, limited-privilege security credentials. It’s the engine behind IAM roles — when a user, service, or another account “assumes a role,” STS hands back short-lived credentials.

Where it shows up

The tell is “temporary credentials,” “assume a role,” or “cross-account/federated access.” STS powers AssumeRole (cross-account), federation with corporate identity providers, and the temporary creds that EC2/Lambda roles use. Long-term keys are what STS lets you avoid.

Test yourself

Practice question

Users authenticated by your corporate identity provider need temporary AWS credentials to access resources, with no long-term keys. What provides these?

  1. IAM user access keys
  2. AWS STS (temporary credentials via role assumption)
  3. A root account key
  4. A bucket policy
👉 Click to reveal the answer & explanation

Correct answer: B. STS issues temporary, limited-privilege credentials when a role is assumed — the basis for federation and cross-account access with no long-term keys. IAM user keys (A) and root keys (C) are long-term secrets; a bucket policy (D) controls resource access, not credential issuance.

Related topics

AWS IAM · IAM roles vs policies · Amazon Cognito

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access