Service Comparison

IAM User vs IAM Role

Users are long-lived identities. Roles are assumed for temporary credentials.

What They Have in Common

Each option can solve part of the scenario. The exam expects you to choose the one that satisfies the stated constraints with the right operational burden, security boundary, availability model, and cost behavior.

Key Differences

OptionPrimary modelBest useSecurityAvailabilityOperations and cost
IAM userLong-lived principalRare workforce or legacy programmatic access when federation is unavailableMFA, access key rotation, least privilegeCredential lifecycle burden
IAM roleAssumable identityEC2/Lambda/ECS workload access, cross-account, federationTrust policy, permissions policy, STSPreferred for temporary access

Typical Exam Clues

Practice After Studying

Return to the certification guide that includes this comparison and launch domain training from there.

Sources and Review Metadata

This independent training application is not affiliated with or endorsed by Amazon Web Services. AWS, Amazon Web Services, and AWS certification names are trademarks of Amazon.com, Inc. or its affiliates.