STS issues temporary, limited-privilege security credentials. It’s the engine behind IAM roles — when a user, service, or another account “assumes a role,” STS hands back short-lived credentials.
Where it shows up
The tell is “temporary credentials,” “assume a role,” or “cross-account/federated access.” STS powers AssumeRole (cross-account), federation with corporate identity providers, and the temporary creds that EC2/Lambda roles use. Long-term keys are what STS lets you avoid.
Test yourself
Users authenticated by your corporate identity provider need temporary AWS credentials to access resources, with no long-term keys. What provides these?
- IAM user access keys
- AWS STS (temporary credentials via role assumption)
- A root account key
- A bucket policy
👉 Click to reveal the answer & explanation
Correct answer: B. STS issues temporary, limited-privilege credentials when a role is assumed — the basis for federation and cross-account access with no long-term keys. IAM user keys (A) and root keys (C) are long-term secrets; a bucket policy (D) controls resource access, not credential issuance.
Related topics
AWS IAM · IAM roles vs policies · Amazon Cognito
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first