Courseiva

SCS-C02 Management and Security Governance Practice Question

A company wants to ensure that IAM users with console access have strong passwords. Which IAM password policy setting should the company configure to enforce the use of at least one uppercase letter?

⚠ Common exam trap

SCS-C02 often tests the specific IAM password policy settings and their exact enforcement, so candidates must distinguish between length, uppercase, lowercase, numbers, and symbols requirements rather than assuming any complexity setting enforces uppercase.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

RequireUppercaseCharacters

The IAM password policy setting `RequireUppercaseCharacters` specifically enforces that IAM user passwords contain at least one uppercase letter (A-Z). When enabled, any password created or changed must include an uppercase character, otherwise IAM rejects it. This directly satisfies the requirement to enforce uppercase letters for console users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MinimumPasswordLength

    Why it's wrong here

    MinimumPasswordLength sets only the character count, not the character types used. The stem requires at least one uppercase letter, which length alone cannot enforce. MinimumPasswordLength would be correct when the policy must guarantee passwords reach a specified number of characters.

  • ✓

    RequireUppercaseCharacters

    Why this is correct

    RequireUppercaseCharacters is the password policy parameter that forces every IAM user password to contain at least one uppercase letter, directly satisfying the stated requirement for console users. Setting it to true makes IAM reject any password lacking an uppercase character at creation or change time.

  • ✗

    RequireNumbers

    Why it's wrong here

    RequireNumbers enforces at least one numeric character, not an uppercase letter. The stem asks specifically for uppercase enforcement, which this setting does not address. RequireNumbers would be correct when the policy must guarantee digits appear in every IAM user password.

  • ✗

    RequireSymbols

    Why it's wrong here

    RequireSymbols enforces non-alphanumeric characters such as ! or #, not uppercase letters. The stem requires uppercase enforcement, which this setting does not provide. RequireSymbols would be correct when the policy must guarantee punctuation or special characters appear in passwords.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.