Courseiva
Security and Compliance →hardMultiple Choice

CLF-C02 Security and Compliance Practice Question

A company's security policy requires that access keys for IAM users must be rotated every 90 days. Which AWS service can automatically detect users with non-compliant key age?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Config's compliance rules (which evaluate resource configurations like key age) with CloudTrail's auditing capabilities (which log actions but do not enforce policies), leading them to incorrectly select CloudTrail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config with the access-keys-rotated rule

AWS Config with the 'access-keys-rotated' managed rule automatically checks whether IAM user access keys have been rotated within the specified number of days (default 90). When a key exceeds the configured maximum age, AWS Config flags the resource as non-compliant, enabling automated detection and remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records a complete audit history of all API calls made in your account, including events like 'CreateAccessKey' and 'GetSecretValue'. While this log data could theoretically be used to calculate the age of an access key, CloudTrail does not continuously evaluate keys against a defined rotation policy or proactively flag non-compliant credentials. It is a detective audit service, not a compliance evaluator, so it cannot enforce an automated 90-day rotation check.

  • ✓

    AWS Config with the access-keys-rotated rule

    Why this is correct

    The AWS Config managed rule access-keys-rotated continuously evaluates the age of IAM access keys against a configurable maximum threshold (commonly 90 days). It flags keys that exceed this limit as non-compliant, enabling automated remediation or manual review. Because it is a compliance rule, it proactively enforces your organization's credential rotation policy without requiring you to write custom code.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a continuous security monitoring service that uses machine learning, anomaly detection, and threat intelligence to detect malicious activity and unauthorized behavior within your AWS environment. It focuses on identifying threats like compromised credentials, unusual API patterns, or cryptocurrency mining — not on evaluating whether access keys have been rotated within a 90-day window. Therefore, it cannot serve as a compliance check for key rotation policies.

  • ✗

    AWS IAM Access Analyzer

    Why it's wrong here

    AWS IAM Access Analyzer helps you understand resource access by analyzing policies and identifying resources that can be accessed from outside your AWS account. It also generates least-privilege IAM policies based on observed access activity, but it does not track the creation date or rotation status of access keys. As a result, it is not designed to assess compliance with a credential rotation schedule like the 90-day rule.

About these practice questions

This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.