Courseiva

SCS-C02 Management and Security Governance Practice Question

A company wants to centrally manage access keys for all IAM users across multiple accounts. Which AWS service should be used to rotate access keys automatically?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS IAM

AWS IAM is the service that manages IAM users and access keys. While there is no built-in automatic rotation feature in IAM, you can automate access key rotation using IAM APIs or the AWS CLI. Among the given options, AWS IAM is the correct choice because it directly handles access keys. AWS STS provides temporary credentials, not access key management. AWS Secrets Manager can store secrets but cannot automatically rotate IAM access keys. AWS CloudHSM is for hardware-based cryptographic key storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS STS

    Why it's wrong here

    AWS STS is a web service that issues temporary, time-limited credentials through operations like AssumeRole, GetFederationToken, and GetSessionToken. These short-lived credentials reduce reliance on long-term keys, but STS does not expose any API to create, update, disable, or delete IAM user access keys. It is therefore not the service used for centrally managing or rotating IAM access keys.

  • ✓

    AWS IAM

    Why this is correct

    AWS IAM is the only service that owns the lifecycle of IAM user access keys through CreateAccessKey, UpdateAccessKey, and DeleteAccessKey APIs. Because IAM does not provide built-in scheduling for rotation, central management must be implemented as custom automation (for example, a Lambda function invoked by Amazon EventBridge) that rotates keys across accounts using IAM APIs. IAM also tracks access key status and last-used metadata, which supports a central auditing and rotation process.

  • ✗

    AWS Secrets Manager

    Why it's wrong here

    AWS Secrets Manager stores secrets centrally and can automatically rotate supported credentials such as Amazon RDS database passwords by calling a Lambda rotation function. It has no built-in rotation template or API integration for IAM user access keys, so it cannot update or create new IAM access keys for IAM users. At most it acts as a vault, not as the manager that rotates IAM credentials.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM provides dedicated hardware security modules for protecting and performing cryptographic operations with symmetric and asymmetric keys, such as TLS keys or encryption keys. IAM access keys are not cryptographic key material stored in an HSM; they are long-term AWS API authentication credentials whose lifecycle is governed by IAM. CloudHSM therefore cannot rotate or centrally manage IAM access keys.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.