SCS-C02 Management and Security Governance Practice Question
A company has a requirement that all IAM users must use strong passwords. The security engineer needs to enforce a password policy that requires minimum 12 characters, at least one uppercase letter, and at least one number. The engineer sets the password policy in IAM. However, existing users with weak passwords are not forced to change them. What should the engineer do to enforce the policy for existing users?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the password expiration period to 0 to force immediate password change.
Setting the password policy to expire existing passwords will force users to change them on next login. Option A is wrong because the policy is already set; users are not forced to change. Option B is wrong because allowing users to change passwords does not enforce the policy. Option C is wrong because resetting passwords manually is not scalable and not required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually reset each user's password to a strong password.
Why it's wrong here
Manually resetting each user's password is an administrative one-off action that does not modify the account-level password policy or enforce future compliance. Even if you supply a strong temporary password, the user can immediately change it—unless your password policy already rejects weak passwords—and there is no guarantee that every user across the account is covered in a timely manner. This approach is not operationally feasible for large accounts and does not force existing users to adopt the new strong-password standard.
- ✗
Enable 'Allow users to change their own password' in the policy.
Why it's wrong here
Enabling 'Allow users to change their own password' in the IAM password policy simply grants users the self-service permission to update their password; it does not create any obligation or mechanism to change an existing weak password. Users may continue using their current credentials indefinitely without ever setting a strong password, so this setting alone fails to meet the requirement that all IAM users must use strong passwords. A corresponding expiration or forced-reset setting is necessary.
- ✗
Re-apply the password policy to each user.
Why it's wrong here
The IAM password policy is defined at the AWS account level, not per user, so 're-applying' it to individual users has no meaning and no effect on their current password state. Because the policy automatically governs all IAM users once set, existing passwords remain in force until they expire or are explicitly reset by an administrator. This action addresses no underlying problem and cannot compel users with weak passwords to rotate them immediately.
- ✓
Set the password expiration period to 0 to force immediate password change.
Why this is correct
Setting the 'password expiration period' to 0 in the IAM account password policy causes every existing password to expire immediately, forcing each IAM user to choose a new password at the next sign-in. Because the account-level policy has already defined the required strength, the newly chosen passwords must satisfy those strong-complexity rules. This is the only listed option that enforces the strong-password requirement collectively on all users without requiring manual intervention per user.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.