Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer needs to ensure that all new IAM users are created with a strong password policy enforced. Which action should be taken?

⚠ Common exam trap

SCS-C02 often tests the difference between preventive controls (IAM password policy) and detective controls (AWS Config, Lambda) — candidates pick Config or Lambda because they sound more 'automated', but the requirement is enforcement at creation, which only the native policy provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set a custom IAM password policy in the account

AWS IAM account password policies are configured at the account level and apply to all IAM users created in that account. Setting a custom password policy enforces minimum length, complexity, reuse prevention, and rotation requirements automatically for every new and existing user. This is the native, supported mechanism for enforcing strong passwords across an AWS account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set a custom IAM password policy in the account

    Why this is correct

    Setting a custom IAM password policy is the native, account-wide control that enforces minimum length, complexity, rotation, and reuse restrictions for all IAM users. When any IAM user creates a password or resets a forgotten one, IAM evaluates it against this policy and rejects non-compliant choices, so it directly satisfies the requirement. It is the only option that applies automatically to every new user without custom infrastructure or reliance on post-creation events.

  • ✗

    Use AWS Config to automatically delete users with weak passwords

    Why it's wrong here

    AWS Config is a configuration auditing and compliance service, not a password enforcement or resource deletion service. While the managed rule `iam-password-policy` checks the account's password policy settings, Config cannot inspect the actual password of an IAM user (passwords are stored as salted hashes and never exposed) and it has no built-in capability to delete users. Automating deletion would require a custom remediation action via a Lambda function, and even then Config would still be unable to assess password strength from the user's credential material.

  • ✗

    Create a Lambda function that checks password strength on user creation

    Why it's wrong here

    A Lambda function triggered by user creation events cannot reliably evaluate password strength because a new IAM user is created without a password—the admin supplies a password later through `CreateLoginProfile` or the console-set-password flow. The Lambda would have to subscribe to those later events and, even then, the password value is not present in the CloudTrail event; only the API call metadata is available. This approach adds significant complexity and is a brittle, non-native pattern compared to a simple account password policy.

  • ✗

    Use AWS Secrets Manager to generate passwords

    Why it's wrong here

    Secrets Manager is a service for securely storing and rotating secrets, and its random password generator can create strong passwords, but it does not enforce, validate, or govern the password policies applied when those passwords are actually used to create IAM users. The IAM password policy still applies to the password that is set on the IAM user, and Secrets Manager is completely unaware of that policy—it can generate a password that violates the account policy, which IAM will then reject. Relying on it as a control leaves user-chosen passwords ungoverned.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.