Courseiva

SCS-C02 Management and Security Governance Practice Question

A company has a requirement that all access keys for IAM users must be rotated every 90 days. A security engineer needs to implement an automated solution to identify and disable keys that are older than 90 days. Which approach meets the requirement with the least operational overhead?

⚠ Common exam trap

The trap is selecting a monitoring or notification service (Trusted Advisor, CloudTrail, Access Analyzer) instead of an enforcement service (Config with auto-remediation) when the requirement explicitly asks for automated disabling with least operational overhead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an AWS Config rule with auto-remediation to disable keys older than 90 days.

AWS Config can evaluate IAM access key age against a desired rule (e.g., 'iam-access-key-rotated') and trigger automatic remediation using SSM Automation documents to disable keys older than 90 days. This provides a fully automated, low-overhead solution that continuously enforces the requirement without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Trusted Advisor to check key age and send notifications.

    Why it's wrong here

    Trusted Advisor surfaces access-key age only under Business or Enterprise Support, and its notifications cannot disable a key, leaving remediation manual. It is tempting because Trusted Advisor is a native advisory tool, and it would suit periodic reporting to an operations team rather than automated enforcement.

  • ✗

    Use AWS CloudTrail to monitor CreateAccessKey events and trigger a Lambda function to check key age.

    Why it's wrong here

    CloudTrail records CreateAccessKey events but never emits a signal when a key reaches 90 days, so the Lambda would need its own schedule and state tracking. It is tempting because event-driven Lambda automation is a common pattern, and it would fit reacting to key creation rather than enforcing an age threshold.

  • ✗

    Use IAM Access Analyzer to generate findings for unused keys and manually disable them.

    Why it's wrong here

    IAM Access Analyzer reports unused credentials and access findings; it does not evaluate key age or disable keys, so the 90-day requirement still needs manual intervention. It is tempting because Access Analyzer is the native IAM auditing service, and it would suit identifying unused permissions rather than age-based rotation.

  • ✓

    Use an AWS Config rule with auto-remediation to disable keys older than 90 days.

    Why this is correct

    AWS Config continuously evaluates keys against a custom rule and auto-remediation invokes a remediation action to disable non-compliant keys, removing manual checks. This satisfies the 90-day rotation requirement with least operational overhead, since detection and disabling happen automatically without custom scheduling infrastructure.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.