Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A security audit reveals that an IAM user has long-term access keys that have not been rotated in over 90 days. What is the most secure way to enforce key rotation?

⚠ Common exam trap

The trap here is that candidates focus on 'rotation' as a process (automated or manual) rather than recognizing that the most secure solution is to eliminate the need for rotation entirely by using IAM roles with temporary credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use IAM roles instead of long-term access keys.

A custom Lambda function to rotate keys requires you to build and maintain the rotation logic, permission grants, and secret distribution yourself - AWS IAM has no native, built-in automatic key-rotation feature for access keys, so this approach is at best a partial mitigation with real engineering overhead, and it still leaves long-term static credentials in play between rotations. IAM roles are the superior fix because they remove the need for any long-term key or rotation logic at all.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use an AWS Lambda function to automatically rotate keys.

    Why it's wrong here

    A custom Lambda function would require manual management of its own permissions and rotation logic, introducing potential security gaps and operational overhead, whereas AWS IAM provides a built-in, automated key rotation policy that can be applied directly to the user without custom code. This option is tempting because Lambda is often used for custom automation tasks, and in scenarios where IAM’s native rotation policy does not meet specific compliance requirements—such as rotating keys across multiple AWS accounts or integrating with an external secrets manager—a Lambda-based solution would be the correct choice.

  • ✗

    Manually rotate keys every 90 days.

    Why it's wrong here

    Even when performed consistently, manual rotation of long-term access keys every 90 days does not eliminate the fundamental risk of standing credentials: a leaked key remains valid for the entire rotation window, and the process relies on error-prone, non-automated operational discipline. It also provides no automated revocation or scoping of permissions, and the continued existence of permanent keys increases the blast radius of any compromise, whereas IAM roles issue short-lived, automatically expiring credentials.

  • ✓

    Use IAM roles instead of long-term access keys.

    Why this is correct

    IAM roles are the AWS-recommended alternative because they do not require long-term secrets at all: a principal assumes a role through the AWS Security Token Service (STS) and receives temporary credentials with a configurable lifetime (up to 12 hours for role sessions) that are automatically rotated and expire. These credentials can be further constrained by session policies, preventing privilege escalation, and eliminate the operational burden of rotating static access keys, making them far more secure and auditable.

  • ✗

    Delete the user and create a new one.

    Why it's wrong here

    Deleting the user and recreating it is disruptive to both console and API access, breaking existing applications, scripts, and CI/CD pipelines that depend on the current user ARN, and it forces re-creation of all IAM policies, group memberships, and MFA devices. More importantly, it does not address the root cause of the audit finding—if the new user is given long-term access keys again, the same risk persists; the proper fix is to move the workload to temporary credentials via IAM roles.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.