SCS-C02 Management and Security Governance Practice Question
A company wants to centrally manage access keys for all IAM users across multiple accounts. Which AWS service should be used to rotate access keys automatically?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM
AWS IAM is the service that manages IAM users and access keys. While there is no built-in automatic rotation feature in IAM, you can automate access key rotation using IAM APIs or the AWS CLI. Among the given options, AWS IAM is the correct choice because it directly handles access keys. AWS STS provides temporary credentials, not access key management. AWS Secrets Manager can store secrets but cannot automatically rotate IAM access keys. AWS CloudHSM is for hardware-based cryptographic key storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS STS
Why it's wrong here
AWS STS is a web service that issues temporary, time-limited credentials through operations like AssumeRole, GetFederationToken, and GetSessionToken. These short-lived credentials reduce reliance on long-term keys, but STS does not expose any API to create, update, disable, or delete IAM user access keys. It is therefore not the service used for centrally managing or rotating IAM access keys.
- ✓
AWS IAM
Why this is correct
AWS IAM is the only service that owns the lifecycle of IAM user access keys through CreateAccessKey, UpdateAccessKey, and DeleteAccessKey APIs. Because IAM does not provide built-in scheduling for rotation, central management must be implemented as custom automation (for example, a Lambda function invoked by Amazon EventBridge) that rotates keys across accounts using IAM APIs. IAM also tracks access key status and last-used metadata, which supports a central auditing and rotation process.
- ✗
AWS Secrets Manager
Why it's wrong here
AWS Secrets Manager stores secrets centrally and can automatically rotate supported credentials such as Amazon RDS database passwords by calling a Lambda rotation function. It has no built-in rotation template or API integration for IAM user access keys, so it cannot update or create new IAM access keys for IAM users. At most it acts as a vault, not as the manager that rotates IAM credentials.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM provides dedicated hardware security modules for protecting and performing cryptographic operations with symmetric and asymmetric keys, such as TLS keys or encryption keys. IAM access keys are not cryptographic key material stored in an HSM; they are long-term AWS API authentication credentials whose lifecycle is governed by IAM. CloudHSM therefore cannot rotate or centrally manage IAM access keys.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.