Courseiva

SCS-C02 Identity and Access Management Practice Question

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that no IAM user can have an access key older than 90 days. What is the MOST efficient way to achieve this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an SCP in the root organizational unit that denies IAM actions if the access key age exceeds 90 days.

A service control policy (SCP) applied at the root organizational unit centrally enforces the 90-day access key age limit across all accounts. SCPs can use a condition like 'aws:AccessKeyAge' to deny actions (e.g., 'iam:CreateAccessKey') when the age exceeds 90 days. This is the most efficient because it's a single policy that applies to all accounts without per-account configuration or manual auditing. Option B (AWS Config) is reactive—it only sends alerts and does not prevent excessive key age. Option C (IAM policy in each account) requires deploying a policy to every account individually, which is less efficient and prone to gaps. Option D disables IAM user creation entirely, which is too restrictive and does not address existing old access keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use an SCP in the root organizational unit that denies IAM actions if the access key age exceeds 90 days.

    Why this is correct

    A service control policy (SCP) applied at the root organizational unit centrally enforces the 90-day access key age limit across all accounts. SCPs can use a condition like 'aws:AccessKeyAge' to deny actions (e.g., 'iam:CreateAccessKey') when the age exceeds 90 days. This is the most efficient because it's a single policy that applies to all accounts without per-account configuration or manual auditing.

  • ✗

    Use AWS Config rules to detect old access keys and send alerts.

    Why it's wrong here

    AWS Config rules are detective, not preventive. A rule can evaluate IAM access keys against a 90-day threshold and trigger alerts or invoke a remediation action, but it does not block API calls made by an old key in real time. Enforcement depends on the remediation logic and may leave a gap between detection and action. An SCP with the aws:AccessKeyAge condition denies the request natively, which is more immediate and centrally enforced.

  • ✗

    Use an IAM policy in each account that denies access if the key age exceeds 90 days.

    Why it's wrong here

    An IAM policy with an aws:AccessKeyAge condition could technically deny actions for old keys, but it would need to be attached to every IAM principal in every account and maintained per account. This creates operational overhead and gaps if any principal is missed or a new account is added. SCPs are inherited from the root organizational unit, so one policy applies to all accounts and principals, making the SCP solution far more efficient and less error-prone.

  • ✗

    Use an SCP to disable IAM user creation.

    Why it's wrong here

    An SCP that denies iam:CreateUser only prevents the creation of new IAM users; it does not evaluate the age of existing access keys. Any users or keys already in the environment would remain active and continue to be usable for longer than 90 days, so the requirement would not be enforced. It also imposes a blanket restriction on creating IAM users, which may be overly broad if the organization legitimately needs IAM users, rather than targeting the rotation policy specifically.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.