SCS-C02 Identity and Access Management Practice Question
Which TWO of the following are best practices for managing IAM user credentials? (Choose TWO.)
⚠ Common exam trap
SCS-C02 often tests the misconception that convenience (shared users, hardcoded keys) is acceptable, when the exam expects you to recognize that identity isolation, MFA, and short-lived credentials are non-negotiable security controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable MFA for all IAM users.
Option C is correct because enabling multi-factor authentication (MFA) for all IAM users adds a second authentication factor beyond the password, significantly reducing the risk of credential compromise if a password is leaked or guessed. Option D is correct because regularly rotating access keys limits the window of exposure if a key is compromised and aligns with AWS security best practices for credential lifecycle management. Option A is incorrect because sharing a single IAM user across multiple developers eliminates individual accountability and makes it impossible to audit or revoke access per person; each developer should have a unique IAM user or federated identity. Option B is incorrect because storing access keys in source code repositories exposes them to anyone with repository access and is a common cause of credential leakage; secrets should be stored in AWS Secrets Manager or similar. Option E is incorrect because relying on long-term access keys for all users increases risk; temporary credentials via IAM roles or AWS STS are preferred where possible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a single IAM user for multiple developers.
Why it's wrong here
A single IAM user shared by multiple developers means all actions in CloudTrail are attributed to that one identity, so you cannot determine which developer made changes or which access key use is attributable to whom. This undermines auditing and incident response, and credential revocation becomes disruptive because every developer must receive new credentials. IAM is designed for one unique identity per human or workload.
- ✗
Store access keys in source code repositories for convenience.
Why it's wrong here
Committing AWS access keys to a source code repository is dangerous because any individual with read access to the repo, and any automated secret-scanning bot that monitors public repositories, can extract live credentials and assume the permissions attached to that IAM user. Even in a private repo, the keys may be exposed through forks, CI logs, or third-party integrations. Credentials should be supplied through environment references, AWS Secrets Manager, or IAM roles instead.
- ✓
Enable MFA for all IAM users.
Why this is correct
Enabling MFA for all IAM users is a core AWS security best practice because it requires something the user has, such as a TOTP device or U2F key, in addition to a password or access key. This materially reduces the risk that a stolen password or access key alone can be used to access the account, and AWS recommends MFA for every user including root. MFA protects against credential theft and is an explicit requirement for privileged accounts in many compliance frameworks.
- ✓
Rotate access keys regularly.
Why this is correct
Regular access-key rotation is a best practice because it limits the exposure window if a key is compromised or accidentally disclosed. By creating a new key, updating applications, and then deactivating and deleting the old key, you ensure that any leaked key becomes invalid and cannot be used indefinitely. AWS also provides LastUsed information to help identify unused keys that should be removed, and this practice works with short-lived sessions to reduce overall credential risk.
- ✗
Use long-term access keys for all users.
Why it's wrong here
Using long-term access keys for all users contradicts the AWS recommended practice of using temporary credentials obtained via IAM roles and AWS STS. Long-term keys do not expire, so once issued they remain valid until manually rotated or deleted, creating a persistent risk if leaked and adding overhead to manage their lifecycle. Temporary credentials, by contrast, automatically expire after a configurable duration and can be scoped to specific sessions, making them the safer default.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.