CLF-C02 Security and Compliance Practice Question
A company's security policy requires that access keys for IAM users must be rotated every 90 days. Which AWS service can automatically detect users with non-compliant key age?
⚠ Common exam trap
A common mix-up: candidates confuse AWS Config's compliance rules (which evaluate resource configurations like key age) with CloudTrail's auditing capabilities (which log actions but do not enforce policies), leading them to incorrectly select CloudTrail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with the access-keys-rotated rule
AWS Config with the 'access-keys-rotated' managed rule automatically checks whether IAM user access keys have been rotated within the specified number of days (default 90). When a key exceeds the configured maximum age, AWS Config flags the resource as non-compliant, enabling automated detection and remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records a complete audit history of all API calls made in your account, including events like 'CreateAccessKey' and 'GetSecretValue'. While this log data could theoretically be used to calculate the age of an access key, CloudTrail does not continuously evaluate keys against a defined rotation policy or proactively flag non-compliant credentials. It is a detective audit service, not a compliance evaluator, so it cannot enforce an automated 90-day rotation check.
- ✓
AWS Config with the access-keys-rotated rule
Why this is correct
The AWS Config managed rule access-keys-rotated continuously evaluates the age of IAM access keys against a configurable maximum threshold (commonly 90 days). It flags keys that exceed this limit as non-compliant, enabling automated remediation or manual review. Because it is a compliance rule, it proactively enforces your organization's credential rotation policy without requiring you to write custom code.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a continuous security monitoring service that uses machine learning, anomaly detection, and threat intelligence to detect malicious activity and unauthorized behavior within your AWS environment. It focuses on identifying threats like compromised credentials, unusual API patterns, or cryptocurrency mining — not on evaluating whether access keys have been rotated within a 90-day window. Therefore, it cannot serve as a compliance check for key rotation policies.
- ✗
AWS IAM Access Analyzer
Why it's wrong here
AWS IAM Access Analyzer helps you understand resource access by analyzing policies and identifying resources that can be accessed from outside your AWS account. It also generates least-privilege IAM policies based on observed access activity, but it does not track the creation date or rotation status of access keys. As a result, it is not designed to assess compliance with a credential rotation schedule like the 90-day rule.
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.