SCS-C02 Management and Security Governance Practice Question
A security engineer needs to provide a detailed report of all IAM users, their access keys, and the last time each key was used, to identify unused credentials. Which AWS service or feature should the engineer use to generate this report?
⚠ Common exam trap
The trap here is thinking that CloudTrail logs can easily provide last used dates for access keys, but CloudTrail logs record API calls, not a summary of credential usage, and would require significant effort to aggregate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM credential report
The IAM credential report is specifically designed to provide a comprehensive list of IAM users and their credential details, including last used information for access keys. It is generated on demand and can be downloaded as a CSV. Other services like CloudTrail, Trusted Advisor, and GuardDuty do not offer this consolidated view, making the credential report the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior. It does not generate reports on IAM user credentials or their last usage. Using GuardDuty would not provide the needed inventory of users and key usage.
- ✓
IAM credential report
Why this is correct
The IAM credential report provides a CSV file listing all IAM users and the status of their credentials, including passwords, access keys, MFA devices, and the last used date for each. It is the most direct way to obtain the required information for identifying unused credentials.
- ✗
AWS CloudTrail logs
Why it's wrong here
CloudTrail logs record API activity but do not provide a consolidated report of IAM users and their credential status. You could parse logs to find usage, but it would not include all users or their credential metadata. It is not the efficient or intended tool for this purpose.
- ✗
AWS Trusted Advisor
Why it's wrong here
Trusted Advisor offers security checks, such as identifying IAM users with access keys, but it does not provide a detailed report of last used dates for each key. It gives recommendations but lacks the granular per-key usage data required for this analysis.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.