A company has a requirement that all access keys for IAM users must be rotated every 90 days. A security engineer needs to implement an automated solution to identify and disable keys that are older than 90 days. Which approach meets the requirement with the least operational overhead?
AWS Config continuously evaluates keys against a custom rule and auto-remediation invokes a remediation action to disable non-compliant keys, removing manual checks. This satisfies the 90-day rotation requirement with least operational overhead, since detection and disabling happen automatically without custom scheduling infrastructure.
Why this answer
AWS Config can evaluate IAM access key age against a desired rule (e.g., 'iam-access-key-rotated') and trigger automatic remediation using SSM Automation documents to disable keys older than 90 days. This provides a fully automated, low-overhead solution that continuously enforces the requirement without manual intervention.
Exam trap
The trap is selecting a monitoring or notification service (Trusted Advisor, CloudTrail, Access Analyzer) instead of an enforcement service (Config with auto-remediation) when the requirement explicitly asks for automated disabling with least operational overhead.
How to eliminate wrong answers
Option A is wrong because AWS Trusted Advisor only provides notifications and does not automatically disable keys, requiring manual action and thus higher operational overhead. Option B is wrong because CloudTrail logs CreateAccessKey events but does not natively evaluate key age; building a custom Lambda solution adds development and maintenance overhead. Option C is wrong because IAM Access Analyzer identifies unused permissions and generates findings, but it does not automatically disable keys and still requires manual remediation.