Essential cookies keep authentication working. With your permission, we also use analytics cookies to understand and improve the product. Read our Privacy Policy

DataEngPrep.tech
QuestionsPracticeAI CoachDashboardPricingBlog
ProLogin
Home/Questions/Cloud/Tools/How does the trust relationship policy in IAM roles work?

How does the trust relationship policy in IAM roles work?

Cloud/Toolseasy2 min read

Reviewed by Aditya Kumar · Last reviewed 2026-08-08

An IAM role's trust relationship policy, often called a trust policy, is a resource based policy attached directly to the role that defines who is allowed to assume it. It acts as a gatekeeper,…

🤖 Analyze Your Answer
Frequency
Low
Asked at 1 company
Category
179
questions in Cloud/Tools
Difficulty Split
104E|27M|48H
in this category
Total Bank
1,863
across 7 categories
Asked at these companies
Capco

Why This Question Matters

This easy-level Cloud/Tools question appears frequently in data engineering interviews at companies like Capco. While less common, it tests deeper understanding that distinguishes strong candidates.

How to Approach This

Start by clearly defining the core concept being asked about. Interviewers want to see that you understand the fundamentals before diving into implementation details. Structure your answer with a definition, then explain the practical application with a concise example. The expert answer includes a code example that demonstrates the implementation pattern.

Expert Answer
337 wordsIncludes code

An IAM role's trust relationship policy, often called a trust policy, is a resource-based policy attached directly to the role that defines who is allowed to assume it. It acts as a gatekeeper, specifying the principals (users, roles, AWS accounts, or AWS services) that can initiate the sts:AssumeRole action.

How It Works

When a principal attempts to assume an IAM role, AWS Security Token Service (STS) evaluates the role's trust policy. This policy must explicitly grant the sts:AssumeRole action to the requesting principal. If the trust policy permits the assumption, STS issues temporary security credentials (access key ID, secret access key, and session token) to the principal. These temporary credentials then allow the principal to perform actions defined by the role's permissions policy, which is separate and dictates what the role can do once assumed. The trust policy is fundamental for cross-account access, granting permissions to AWS services, or enabling federated users.

Policy Structure and Best Practices

Trust policies are defined in JSON. The Principal element specifies the entity allowed to assume the role. This can be an AWS account (e.g., arn:aws:iam::123456789012:root), an IAM user, another IAM role, or an AWS service (e.g., ec2.amazonaws.com). The Action must be sts:AssumeRole.

Conditions can be added for enhanced security. For instance, sts:ExternalId is crucial for cross-account roles to prevent the "confused deputy" problem, ensuring only an intended third party can assume the role. Other common conditions include aws:SourceIp (restricting by IP address) or aws:MultiFactorAuthPresent (requiring MFA).

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::123456789012:root"
      },
      "Action": "sts:AssumeRole",
      "Condition": {
        "StringEquals": {
          "sts:ExternalId": "my-unique-external-id"
        }
      }
    }
  ]
}

Best practices include applying the principle of least privilege by specifying exact principals, using conditions like sts:ExternalId for cross-account access, and avoiding * in the Principal element unless absolutely necessary for specific AWS service roles.

In the interview, also mention the crucial distinction between the trust policy (who can assume the role) and the permissions policy (what actions the role can perform once assumed).

⚡
Pro Tip

Red Flag: Trust policy with * principal. Pro-Move: 'We use conditions: MFA and source IP—assume only from corporate network with MFA.'

Want all answers as a PDF for offline study?
Seven focused volumes with 750+ in-depth answers — Answer Vault →

Related Cloud/Tools Questions

easyWhat are Airflow Operators? Give examples.FreeeasyExplain the difference between Azure Data Factory (ADF) and Databricks.FreeeasyHow do you handle data security and compliance in a cloud environment?FreehardWhat are the key components of AWS Glue, and how do they work together?FreeeasyWhat is Azure Data Factory (ADF), and what are its main components?Free

Level up your prep

Recommended
Educative
Educative Unlimited

800+ hands-on courses — Grokking System Design, Coding Patterns, and AI mock interviews for your DE loop.

Start learning →

Some links below are affiliate links. If you buy through them we may earn a small commission at no extra cost to you — it helps keep DataEngPrep free.

According to DataEngPrep.tech, this is one of the most frequently asked Cloud/Tools interview questions, reported at 1 company. DataEngPrep.tech maintains an editor-reviewed database of 1,863 data engineering interview questions across 7 categories.

← Back to all questionsMore Cloud/Tools questions →
Categories
All QuestionsSQLSpark / Big DataPython / CodingSystem DesignCloud / ToolsBehavioral
By Company
AmazonGoogleDatabricksSnowflakeAWSAzureMicrosoftNetflixUberTCS
Interview Guides
All GuidesTop SQL QuestionsTop Spark QuestionsPySpark QuestionsTop Python QuestionsTop System DesignKafka QuestionsAirflow QuestionsSQL Window FunctionsETL QuestionsData Modeling
Products
AI Interview CoachAnswer AnalyzerSQL PlaygroundResume AnalyzerAnswer Vault PDFsPricing
Company
About & Editorial PolicyContact UsAI DisclosureDisclaimerTerms of ServicePrivacy Policy
© 2026 DataEngPrep.tech. All rights reserved.
AboutBlogContactDisclaimer