SCS-C02 Management and Security Governance Practice Question
A security auditor needs to view a list of all IAM users, including their last activity timestamps, for a compliance review. Which AWS service provides this information natively?
⚠ Common exam trap
The trap is confusing activity logging (CloudTrail) with credential inventory (credential report) — candidates pick CloudTrail because it 'shows activity', but it does not natively produce a per-user last-activity list.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM credential report
The AWS IAM credential report is a native feature that generates a CSV containing all IAM users, their access keys, password status, MFA status, and key rotation dates including last activity timestamps. It is specifically designed for auditing user credentials and activity, making it the correct choice for a compliance review of last activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API calls and management events, including IAM actions such as ListUsers or CreateUser, but it is a time-ordered audit log rather than a current-state inventory. Searching CloudTrail could reveal that users were created or listed, but it cannot produce a single consolidated roster of every current IAM user with password and access-key metadata. Therefore, it does not meet the auditor's need for a user/credential report.
- ✗
IAM Access Analyzer
Why it's wrong here
IAM Access Analyzer continuously analyzes resource-based policies—such as S3 bucket policies, KMS key policies, and IAM role trust policies—to identify resources shared outside your account. It does not enumerate IAM users or track their console logins, password age, or access-key usage. Its purpose is detecting unintended external access, not producing an inventory or activity report for IAM principals.
- ✓
AWS IAM credential report
Why this is correct
The IAM credential report is a CSV exported through the console or via GenerateCredentialReport/GetCredentialReport APIs that lists every IAM user in the account. It includes password last used and rotation status, access key IDs and their last-used/rotation dates, MFA device presence, and whether the user has a password. This report directly answers the auditor's need for a complete, current list of IAM users plus their credential hygiene.
- ✗
AWS Config
Why it's wrong here
AWS Config records supported AWS resource configurations and their changes over time, allowing you to evaluate compliance rules, but it does not generate an activity or credential summary for IAM users. Although Config can track IAM resources and flag rules such as "MFA enabled" or "access key rotated," it cannot report actual last-login timestamps or access-key last-used dates in the way a credential report does. Thus, it is incorrect for this audit request.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.