Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer needs to provide a detailed report of all IAM users, their access keys, and the last time each key was used, to identify unused credentials. Which AWS service or feature should the engineer use to generate this report?

⚠ Common exam trap

The trap here is thinking that CloudTrail logs can easily provide last used dates for access keys, but CloudTrail logs record API calls, not a summary of credential usage, and would require significant effort to aggregate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IAM credential report

The IAM credential report is specifically designed to provide a comprehensive list of IAM users and their credential details, including last used information for access keys. It is generated on demand and can be downloaded as a CSV. Other services like CloudTrail, Trusted Advisor, and GuardDuty do not offer this consolidated view, making the credential report the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior. It does not generate reports on IAM user credentials or their last usage. Using GuardDuty would not provide the needed inventory of users and key usage.

  • ✓

    IAM credential report

    Why this is correct

    The IAM credential report provides a CSV file listing all IAM users and the status of their credentials, including passwords, access keys, MFA devices, and the last used date for each. It is the most direct way to obtain the required information for identifying unused credentials.

  • ✗

    AWS CloudTrail logs

    Why it's wrong here

    CloudTrail logs record API activity but do not provide a consolidated report of IAM users and their credential status. You could parse logs to find usage, but it would not include all users or their credential metadata. It is not the efficient or intended tool for this purpose.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    Trusted Advisor offers security checks, such as identifying IAM users with access keys, but it does not provide a detailed report of last used dates for each key. It gives recommendations but lacks the granular per-key usage data required for this analysis.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.